background preloader

SecLists.Org Security Mailing List Archive

SecLists.Org Security Mailing List Archive

Éviter les failles de sécurité dès le développement d'une application - 2 ArticleCategory: Software Development AuthorImage: TranslationInfo: Original in fr Frédéric Raynal, Christophe Blaess, Christophe Grenier fr to en Georges Tarbouriech AboutTheAuthor: Christophe Blaess est un ingénieur indépendant dans le domaine de l'aéronautique Passionné par Linux, il effectue l'essentiel de son travail sur ce système, et assure la coordination des traductions des pages de manuel publiées par le Linux Documentation Project. Christophe Grenier est étudiant en 5ème année à l'ESIEA, où il est également administrateur système. Frédéric Raynal utilise Linux depuis de nombreuses années car ça ne polue pas, ça n'utilse pas d'hormones, d'OGM ou de farines animales ... rien que de la sueur et de l'astuce. Abstract Notre série d'articles essaye de mettre en lumière les principales failles de sécurité susceptibles d'apparaître dans une application, afin de présenter les moyens permettant de les éviter en modifiant quelque peu les habitudes de développement. ArticleIllustration ArticleBody

Tutorial: Facebook RSS feed Every Facebook page has an RSS feed. You can subscribe to that feed with your RSS reader. You can also embed it or build applications that use it and everything else you can do with an RSS feed. The only thing is, finding the URL of the feed can be difficult, so i decided to help a little and write this guide. Example use case

Ch01: Configuring Cisco PIX Firewalls Sometimes you may have a Cisco PIX 501 firewall protecting your DSL based home network. This chapter covers how to configure it and in addition, there are a number of fully commented sample PIX configurations in the appendix in which each line is explained. It is important to remember that the PIX 501 has two Ethernet interfaces. The named "outside" should always be connected to the Internet and the one labeled "inside" should be connected to your home network. Network address translation is a method used to help conserve the limited number of IP addresses available for internet purposes. There are many ways to access the PIX command line. Via The Console Port Your Cisco PIX will come with a console cable that will allow you to configure your PIX using terminal emulation software such as Hyperterm. Via Telnet One easy way to get access to any device on your network is using the /etc/hosts file. Once connected to the network you can access the PIX via telnet Configuring DSL PPPoE DHCP

How ‘Social Intelligence’ Can Guide Decisions By offering decision makers rich real-time data, social media is giving some companies fresh strategic insight. In many companies, marketers have been first movers in social media, tapping into it for insights on how consumers think and behave. As social technologies mature and organizations become convinced of their power, we believe they will take on a broader role: informing competitive strategy. In particular, social media should help companies overcome some limits of old-school intelligence gathering, which typically involves collecting information from a range of public and propriety sources, distilling insights using time-tested analytic methods, and creating reports for internal company “clients” often “siloed” by function or business unit. Today, many people who have expert knowledge and shape perceptions about markets are freely exchanging data and viewpoints through social platforms. Exhibit 1: From identifying data to mapping people and conversations Exhibit 2: Notes 1. 2.

Apprendre le hacking - Les bases du hack et la sécurité informatique, le site du vrai hacking Vous en aviez peut-être entendu parler : le 1er février 2008, Wojciech Purczynski a rapporté aux développeurs du kernel Linux une vulnérabilité critique touchant un appel système, sys_vmsplice(). La vulnérabilité a été rendue publique le 8 février, soumise au bugtraq le 12 et a permis le piratage d'une multitude de serveurs à travers le monde, malgré la rapidité de correction de la faille. Effectivement, la PoC (Proof Of Concept) largement diffusée permet de gagner les droits root sur n'importe quelle machine Linux Intel 32 bits. Bien sûr, l'exploitation est possible sous d'autres architectures avec un programme adapté. Depuis 5 ans qu'elle traîne ici, elle est un peu dépassée, mais permet d'appréhender les problématiques liées aux vulnérabilités du kernel. I°) Le noyau linux : les bases Un noyau monolithique D'après Tanenbaum, l'architecture du noyau de Linux était censé condamner celui-ci à tomber aux oubliettes (cf. le très célèbre mail Linux is obsolete).

Halalbook, le réseau social des musulmans Fun with network Scangear Updated Dec 20 2002 The iR Port Forwarder Page This page has been put together to assist you in connecting a single iR pull scanning product into a multi network/subnet environment Update Oct 24 2002 Network Scangear V 1.4 now supports subnet scanning Click here to download the Port Forwarder 1. 2. 3. 4. 5. The iR product will require a network/subnet. Lets use the following IP addresses for the Port Forwarder NICS and iR product. NIC 1 192.168.10.10 IP Address of Port Forwarder NIC 1 (Connected to Subnet 1) NIC 2 192.168.20.10 IP Address of Port Forwarder NIC 2 (Connected to Subnet 2) NIC 3 192.168.30.10 IP Address of Port Forwarder NIC 3 (Connected to Subnet 3) NIC 4 192.168.0.10 IP Address of Port Forwarder NIC 4 (Connected to iR Product) iR Product 192.168.0.100 IP Address of iR product Once configured correctly, the Port Forwarder will forward all TCP/UDP/IPX packets received on NIC 1, NIC 2 and NIC 3 directly to the iR Product 6. 7. 8. 9. 10. Here is an example; 11. 12. 13. 14. 1.

Guerilla researcher created epic botnet to scan billions of IP addresses In one of the more audacious and ethically questionable research projects in recent memory, an anonymous hacker built a botnet of more than 420,000 Internet-connected devices and used it to perform one of the most comprehensive surveys ever to measure the insecurity of the global network. In all, the nine-month scanning project found 420 million IPv4 addresses that responded to probes and 36 million more addresses that had one or more ports open. A large percentage of the unsecured devices bore the hallmarks of broadband modems, network routers, and other devices with embedded operating systems that typically aren't intended to be exposed to the outside world. The researcher found a total of 1.3 billion addresses in use, including 141 million that were behind a firewall and 729 million that returned reverse domain name system records. There were no signs of life from the remaining 2.3 billion IPv4 addresses. Continually scanning almost 4 billion addresses for nine months is a big job.

Related: