Tuesday, April 27, 2010
Tuesday, March 30, 2010
PenTBox – Penetration Testing Security Suite
PenTBox is a Security Suite that packs security and stability testing oriented tools for networks and systems. Programmed in Ruby and oriented to GNU/Linux systems, but compatible with Windows, MacOS and every systems where Ruby works.
It is free, licensed under GNU/GPLv3.
PenTBox Contains
Cryptography tools
- Base64 Encoder & Decoder
- Multi-Digest (MD5, SHA1, SHA256, SHA384, SHA512)
- Hash Password Cracker (MD5, SHA1, SHA256, SHA384, SHA512)
- Secure Password Generator
- Files en/decryptor Rijndael (AES) 256 bits – GOST – ARC4
Network tools
- TCP Flood DoSer
- TCP Flood AutoDoSer
- Spoofed SYN Flood DoSer [nmap - hping3]
- Port scanner
- Honeypot
- PenTBox Secure Instant Messaging
Extra
- L33t Sp3@k Converter
- Fuzzer
An updated list of tools can be found here.
You can download PenTBox v1.3.2 here:
Windows version (Ruby included) – pentbox_1.3.2_win.zip
Linux version – pentbox_1.3.2.tarOr read more here.
Maybe next year I can win Pwn2Own.
Monday, March 29, 2010
Netflix for Wii: Mario Must be Happy
Saturday, March 13, 2010
Google in The Onion in The Schneier-sphere
March 8, 2010
Google in The Onion
MOUNTAIN VIEW, CA—Responding to recent public outcries over its handling of private data, search giant Google offered a wide-ranging and eerily well-informed apology to its millions of users Monday."We would like to extend our deepest apologies to each and every one of you," announced CEO Eric Schmidt, speaking from the company's Googleplex headquarters. "Clearly there have been some privacy concerns as of late, and judging by some of the search terms we've seen, along with the tens of thousands of personal e-mail exchanges and Google Chat conversations we've carefully examined, it looks as though it might be a while before we regain your trust."
Google expressed regret to some of its third-generation Irish-American users on Smithwood between Barlow and Lake.
Added Schmidt, "Whether you're Michael Paulson who lives at 3425 Longview Terrace and makes $86,400 a year, or Jessica Goldblatt from Lynnwood, WA, who already has well-established trust issues, we at Google would just like to say how very, truly sorry we are."
Posted on March 8, 2010 at 2:24 PM • 15 Comments
To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter.
If only this weren't true.
DISCLAIMER: Note to Indian and Chinese news organizations: The Onion is a "fake" news site and should not be used as a source for stories. Bruce Schneier is a serious security and cryptography expert and should not be used as a source for humor.
Gordon Gecko for President - RE: Premium Prices at thebigquestions.com blog
Greed is good. Okay, maybe I'm overstating. Overwhelming desire for self-preservation and upward mobility is good. Boy, that's sure not as sexy, but it works.
Privacy is Overrated - RE: De-Anonymizing Social Network Users
Ohm's summary of what's happened:
"Reidentification science disrupts the privacy policy landscape by undermining the faith that we have placed in anonymization. This is no small faith, for technologists rely on it to justify sharing data indiscriminately and storing data perpetually, all while promising their users (and the world) that they are protecting privacy. Advances in reidentification expose these promises as too often illusory. These advances should trigger a sea change in the law, because nearly every information privacy law or regulation grants a get-out-of-jail free card to those who anonymize their data....Yet reidentification science exposes the underlying promise made by these laws—that anonymization protects privacy—as an empty one, as broken as the technologists’ promises. At the very least, lawmakers must reexamine every privacy law, asking whether the power of reidentification and fragility of anonymization have thwarted their original designs.
The power of reidentification also transforms the public policy debate over information privacy. Today, this debate centers almost entirely on squabbles over magical phrases like “personally identifiable information” (PII) or “personal data.” Advances in reidentification expose how thoroughly these phrases miss the point. Although it is true that a malicious adversary can use PII like a name or social security number to link data to identity, as it turns out, the adversary can do the same thing using information that nobody would classify as personally identifiable.... These studies [Sweeny, Netflix study, etc.] and others like them sound the death knell for the idea that we protect privacy when we remove PII from our databases. This idea, which has served as the central focus of information privacy law for almost forty years, is a fallacy that has run its course and must now yield to something else."
So, you think you should be able to keep your e-mail, phone number, photos quarantined to just you and a few selected friends? Come on, we all live in public now. Get over it...oh, what's my number? Hey, mind your own business.
Run Your Own Free Proxy Through the Google App Engine - Google Apps - Lifehacker
Privacy, schmivacy. If you don't do anything wrong on the Internet you have nothing to fear. Right?