00:00
00:00
Wurfel-Waffles
Just a super geeky guy who composes music in spare times.

Age 41, Male

Software Developer

TUM

Canada

Joined on 2/9/12

Level:
2
Exp Points:
20 / 50
Exp Rank:
> 100,000
Vote Power:
1.98 votes
Audio Scouts
2
Rank:
Civilian
Global Rank:
> 100,000
Blams:
0
Saves:
1
B/P Bonus:
0%
Whistle:
Normal
Medals:
22
Supporter:
11m 29d

I hope it's secure!

Posted by Wurfel-Waffles - March 11th, 2012


If you are an IT enthusiastic and mainstream-security maniac then you probably keep hearing news media boast nonstop on this and that security hole has/hasn't patch, Anon versus FBI, nonsense DDoS, defacement, MS vs Linux vs Apple, C vs Java for a secure lang and tons of retarted news that aren't helpful much.

The most stand-out topic is: which website or country has the best security system?

Recently, McAfee look-good lists of most secure country is pretty irrelevant. Yet I see many people believe it immediately.

Found 2 bugs on Finish Sewer Control's SCADA servers yesterday that let me gain access to administration, easily. What is the password of the main admin user? Abc123-. Rooted in less than an hour with slight bruteforcing.

Another bug (generic SQL) on Bank of Finland site a week ago. Critical.

Paypal Canada's login data leak. Patched.

Israel Central Bank's website, 13 bugs ranged from XSS to traversal. Some patched, some not yet.

Eurasia login page, DOM XSS. Patched.
_________

I think whoever thought their whatever site is secure should stay humble and shut up about how secure you are. The more you rant about your own server the more happier the attackers are, such as I was.

Be vigilant. Open wills. Be united. And shut your mouth about your security's proud. McAfee was getting paid to lie then I guess?

I think your site is not secure. Oops. I could mean anysite including Newgrounds, right now.


Comments

Personally, I kept up with security, till I hit hit with something that ...
It's an arms race. It's also a defense game.
And everyone online is involved. You're either part of the problem, solution or scenery... waiting to be a victim.
The more involved with computers we got, the scarier it got.

I have a pretty bad habit in pen testing, especially black box testing. I used to leave out small bugs since I aim mostly for critical ones. Those small bugs can turn into critical if current system's condition change.

McAfee is a shithole AV company. 90% of their virus/rootkit database always get from other GNU AV database then they make money on it!

More than 46% of worldwide IT companies ignore or deny their network security weakness. Some even cover the truth on critical vulnerability and REFUSE to patch them.

Look at Nortel, they are going to be bankruptcy in this April. That hack by the Chinese was discovered and reported by their own security adviser. Instead of listened to that guy but they fired him for <personal matters>. Nortel has been wiretapped for over 9 years.

Of course they will all whine shits up when a news post fire up stories on 'Anon skids' or 'the Chinese'. They hacked and r00ted my site/network! Arrest them! That's it?

Wow I didn't know you are online now. Saw your frigging post about Chrome pwnage shit. Good stuff. I might join the fiasco if I have some spare time this week.

Ahem, let's put my grey fedora on again.

Yo, <a href="http://packetstormsecurity.org/news/view/20713/UK-Cybercops-Cuff-Abortion-Clinic-Web-Hack-Suspect.html">http://packetstormsecurity.org/news/view/20713 /UK-Cybercops-Cuff-Abortion-Clinic-Web-Hack-Su spect.html</a> look like another almost-made-it attempt by Anon skids. Didn't mention their name but apparently these assholes forgot to cover their track properly. Where is your TOR now? XD

Also, notice the 26k attempts... in 6 hours. Who the fuck did this news? Even a computer farm (give 6) can't do this within 6 hours. Do you mean packets huh Mr. journalist?

I thought those kids support abortion right? Oh wait, they are Anon, they could be anyone! They are legion, obviously.

SQL inject failed! I bet they used Havij. Why can't they write their own freaking scripts? It takes less than 15 minutes to write a nice & neat PHP script for blind SQL injection.

Dude, I finish recording my tracks. You can find them on my server.

sidenote: most journalists who write story about IT security are a bunch of douches.