Profile_bird

Hey there! taosecurity is using Twitter.

Twitter is a free service that lets you keep in touch with people through the exchange of quick, frequent answers to one simple question: What's happening? Join today to start receiving taosecurity's tweets.

Already using Twitter
from your phone? Click here.

taosecurity

  1. Anyone trying zero-copy BPF http://bit.ly/7DFmNK in FreeBSD 8.0 like Will http://bit.ly/7SOR5O ? Might benchmark with 2 boxes, 7.2 vs 8.0
  2. @ivanristic That's neat, but I can't construct a query to look for SSL servers with a certain configuration or set of capabilities.
  3. @craigbalding Good catches. Like you said, easy to fix if you want to evade notice. So what other services should be added to Shodan?
  4. Thanks to D Webber http://bit.ly/7ZgjA8 for pointing me to SSLscan http://bit.ly/8a89C4 Told John M it might be a nice addition to Shodan
  5. I just learned I should have given thanks for the moon this week http://bit.ly/60C6dM Without it, no life as we know it. Thanks moon!
  6. "Intrusion Tolerance" Vol 12 Iss 4 IATAC http://bit.ly/6RV9XE author prefers survivability to protect-detect-react but fails to explain it!
  7. @CorpPor I use four different operating systems fairly regularly, but I'll let you decide what they might be!
  8. Celebrate the release of FreeBSD 8.0 with a donation to the FreeBSD Foundation -- I just donated $100 -- who's with me? http://bit.ly/8WqoHm
  9. Check out this historical video from 2000 showing the AFCERT and commentary from various notables http://bit.ly/4BU1wZ
  10. As you roll out FreeBSD 8.0, remember to add your dmesg output to the excellent NYCBUG Dmesgd database http://bit.ly/63zRZA
  11. No problem doing binary upgrade on Dell 2950iii or R200 to FreeBSD 8.0 http://bit.ly/5MC9hO from 8.0-RC3 using freebsd-update. Great work!
  12. I can't understand anyone who thinks that a victim of an attack "had it coming" or "deserved it" because he didn't practice "due diligence."
  13. Check out my review of Martin Libicki's Cyberdeterrence and Cyberwar http://bit.ly/7h7BxM Summary: he's wrong; more offense is the answer
  14. Shodan: Another Step Towards Intrusion as a Service http://bit.ly/53TTa9
  15. I predict a mad scramble by intruders during the next 24-48 hours as they use Shodan to locate, own, and secure boxes before others do.
  16. I would not be surprised if shodan.surtri.com disappears in the next few days after receiving a call or two from TLAs or LEAs or .mil's.
  17. shodan.surtri.com is a dream for those wanting to spend Thanksgiving looking for vulnerable boxes, and a nightmare for their owners.
  18. I'm wondering if the Roman Senate debated Imperial immigration policy while Vandals trashed Rome, like current FISMA fans debate "controls."
  19. Chris Eng says it often takes more time to argue about security vulns with devs than it takes to fix them http://bit.ly/6oCkCd He's right!
  20. Kudos to Vivek for explaining the SSL renegotiation exposure http://bit.ly/1NBb62 using his Unsniff network analyzer http://bit.ly/7HTSDg