A new release of Nmap is out! Release 4.20. This release implements a new 2nd generation OS detection system.
Category: Security
The Trackback Validator & co
Fighting against spam is one of the worst job for forum or blogs owners… As everybody, I was hit by nasty bots. It was time to take concrete actions… First, I don’t like the “quick and dirty” fix “Do not allow comments nor trackbacks”. If used correctly, they can greatly
Firewalling with OpenBSD’s PF packet filter
Great tutorial about OpenBSD’s PF… http://home.nuug.no/~peter/pf/
Is greylisting the solution?
As everybody, I’ve too fight against spammers! I’m running my own MTA for several domain names and the box get it 24 hours a day by spammers. I’ve a quite performant SpamAssassin solution in place (~95% of spam is catched) but I’d like to prevent them to reach my SpamAssassing
And now Apple!
After Mc Donalds, which distributes infected MP3 players, Apple detected that some iPods were infected by a Windows virus! When a label “Certified 100% virus free” on the consumer products boxes?
Mc Donalds is bad!
Fast food is not good for your health… But this time, Mc Donalds is really a bad thing… even for your PC! 🙂 Source: Spyware infection prompts McDonalds MP3 recall.
block out log quick on $EXT inet proto icmp
A new physing method appeared a few days ago: now stolen data are sent back to the attackers via ICMP packets! Source: WebSense: Malicious Code / Phishing Alert: Data Stolen via ICMP.
Compromized forum…
Yesterday, while browsing one of my favourites online forum, i was surprised to see it corrupted… A hidden frame with Javascript code, a nice xml.wmf… I contacted the forum admin. Site is currently down. 🙁
OpenSSH & files security
To sync files or export data between servers, I usually use rsync on top of ssh. With public/private key pairs, you can easily automate the jobs via a cron without password issues. I also create a dedicated user who has only the required privileges to run rsync on the destination.
Top Ten passwords in UK
thomas arsenal monkey charlie qwerty 123456 letmein liverpool password 123 Of course this list comes from a study in UK (Liverpool and Arsenal are in good positions) but it must be the same everywhere. I’m sure that the same list in Belgium should contain “Standard” or “Bonnen” 😉 That’s another