Wednesday, March 31, 2010
|
|
Wednesday, March 24, 2010
|
|
- Sell them
- Make fraudulent purchases on them
- Create real-world cards out of them
To create real-world cards, you need blank cards to start with. These are known in the underground as " blank plastic". And there are online stores for blank plastic. Here are some pictures from one:  Above: Collection of "blank" Visa and Master Card cards.  Above: Gold embossing demo. Still missing the hologram sticker.  Above: Finished product. Notice the card holder's name…P.S. Also see our post about credit card holograms.
Wednesday, March 17, 2010
|
|
However, we've rarely shown how these documents were delivered to the targeted, i.e. what the emails looked like. For that kind of information, we can recommend you to visit a blog called Contagio Malware Dump. This blog, run by Mila & co analyses targeted attacks in detail, typically showing the original spoofed emails that started the attacks. Some good examples below — some of them are quite convincing. Would you have opened the PDFs?    More at: contagiodump.blogspot.com
Wednesday, March 10, 2010
|
|
Windows 7 or Snow Leopard, which of these two commercial OS will be harder to hack and why?
Windows 7 is slightly more difficult because it has full ASLR (address space layout randomization) and a smaller attack surface (for example, no Java or Flash by default). Windows used to be much harder because it had full ASLR and DEP (data execution prevention). But recently, a talk at Black Hat DC showed how to get around these protections in a browser in Windows.
No operating system and browser is immune to an attack. And, Flash is the bane of security (well, one of it anyway). In your opinion, which is the safer combination OS+browser to use?
That's a good question. Chrome or IE8 on Windows 7 with no Flash installed. There probably isn't enough difference between the browsers to get worked up about. The main thing is not to install Flash!
The interview was conducted by Matteo Campofiorito at OneITSecurity. You can read the full version here.
|
|