• 11 Aug 2008

    Back in action….

    Had to take a mini-sabbatical to handle some cool things at home...hence the disconnection over the past 3 weeks.Anyway, I'm back in action with lots of new ideas and content....AND, I'm working on my next Security On Wheels audio program - due out soon!...

    Continue Reading...
  • 01 Aug 2008

    My security content from this week

    Here's a screencast I just recorded for TechTarget that you may be interested in:Hacking Windows VistaEnjoy!As always, check out www.principlelogic.com/resources.html for all of my past articles, webcasts, podcasts, and more....

    Continue Reading...
  • 01 Aug 2008

    U.S. randomly confiscating laptops of international travelers

    Yet another reason to encrypt your hard drive...This isn't entirely new but apparently is being brought up again. I just saw on Fox News that international travelers are going to have their laptops randomly confiscated without cause. I presume that's when they're coming back in via U.S. airports.Want my laptop U.S. Customs? Go for it! You're not going to get a bleepity thing off of it...All the name of "fighting ...

    Continue Reading...
  • 25 Jul 2008

    My security content from this week

    Well, again, there is none but I've just written several pieces that'll be out soon. Have a great weekend!Until later......

    Continue Reading...
  • 25 Jul 2008

    Saved by using multiple Web scanners…again.

    I'm in the middle of a project analyzing the security of an e-commerce system. I found a lot of good stuff using WebInspect including one cross-site scripting flaw. However, the cross-site scripting issue was a little lame and next to impossible to re-create. So I decided to turn Acunetix Web Vulnerability Scanner loose on it just to see what it could find. Low and behold...four more cross-site scripting vulns! Wow.Like ...

    Continue Reading...
  • 23 Jul 2008

    $25 billion for information security gaffes?

    What if the government could come running to protect us every time we or one of our colleagues made a bad security decision - intentional or not? Imagine:setting an Allow All rule in your firewallmaking all of your databases accessible via the Internetrevoking any and all password policiesnever testing your systems for vulnerabilities....or,avoiding data backups because, well, you just can...Everything we do in life - every choice we make has ...

    Continue Reading...
  • 23 Jul 2008

    Got a kick out of this “Worry-Free Online Ordering” policy

    I just stumbled across this "worry-free" policy located on an e-commerce site. Very cute...yet sad that a lot of people think SSL and "trust seals" are all that's needed to secure sensitive information in Web apps. ***Your information is safe with us.SOME~ONLINE~STORE ensures your safety and security by employing the highest level internet security system available. All information you provide us via this web site is encrypted using an SSL ...

    Continue Reading...
  • 21 Jul 2008

    Video resume?

    I actually think this is a pretty good idea. We have the technology...why not use it to stand out?Video resume nice, but probably won't land you CIO job...

    Continue Reading...
  • 21 Jul 2008

    What’s wrong with this picture…Circuit City?

    I just stumbled across this "file sharing" site featuring my book Hacking For Dummies...for free download of course. I know, I know, they're not doing anything illegal - they're just providing a way for people to share files. Yeah right. The interesting thing I noted was the "legitimate" companies advertising on the site. WOW...I'm sure the executives at Circuit City would be so proud to know that they're helping sponsor ...

    Continue Reading...
  • 21 Jul 2008

    Do you provide ‘decent’ customer service?

    I've experienced two things in the past week that have reminded me that it doesn't take much to really tick off your customers with bad customer (no) service.1) I ordered some automotive parts 2 weeks ago. Needed them by this past weekend. Never received them. The vendor claimed that UPS lost the package...come to find out the package was apparently addressed to someone else. [don't know for sure since I ...

    Continue Reading...