This is actually a very long story. Most of those who know me well already know the details. If you want them, let’s catch-up for a chat? We have a new business, building motorhomes for the discerning, and creating accessories for New Zealand surfers. You can find the EpicLines landing page at https://www.epiclines.nz.
Hi All. After 104 posts over 8 years, I ve finally managed to move my blog away from the BinaryMist WordPress.com platform to a new platform that will serve the community (us), better going forward. Head on over to binarymist.io/blog for the blog, and binarymist.io for the BinaryMist business site. I ll be explaining the ins and outs [ ]
Risks The shared responsibility model is one that many have not grasped or understood well. Let’s look at the responsibilities of the parties. CSP Responsibility The CSP takes care of the infrastructure, not the customer specific configuration of it, and Due to the shear scale of what they are building, are able to build in [ ]
2017-09-11 Fascicle 1 is now content complete Weighing in at aprox 550 pages incl Additional Resources and Attributions Added links to Network Security Interview between Kim Carter and Haroon Meer on Software Engineering Radio to be released in a day or two Updated threat tags Code formatting changes Punctuation modifications Cloud Ready for technical [ ]
Holistic Info-Sec for Web Developers (F1)(VPS, Network, Cloud, Web Applications) Git Changeset Large number of image updates due to finding that many were not up to scratch when Fascicle 0 went to print. Swapped text images for real images. Many large additions to the VPS chapter and fewer to the Network chapter, such as: * [ ]
Risks Lack of captchas are a risk, but so are captchas themselves Let s look at the problem here? What are we trying to stop with captchas? Bots submitting. What ever it is, whether: Advertising Creating an unfair advantage over real humans Link creation in attempt to increase SEO Malicious code insertion You are more than [ ]
Risks I see this as an indirect risk to the asset of web application ownership (That s the assumption that you will always own your web application). Not being able to introspect your application at any given time or being able to know how the health status is, is not a comfortable place to be in and [ ]
Risks This is where A9 (Using Components with Known Vulnerabilities) of the 2013 OWASP Top 10 comes in. We are consuming far more free and open source libraries than we have ever before. Much of the code we are pulling into our projects is never intentionally used, but is still adding surface area for attack. Much of it: [ ]
Risks Passwords and other secrets for things like data-stores, syslog servers, monitoring services, email accounts and so on can be useful to an attacker to compromise data-stores, obtain further secrets from email accounts, file servers, system logs, services being monitored, etc, and may even provide credentials to continue moving through the network compromising other machines. Passwords and/or…
The following is the process I found to set-up the pass-through of the very common USB TP-LINK TL-WN722N Wifi adapter (which is known to work well with Linux) to a Virtual Host Kali Linux 1.1.0 (same process for 2.0) guest, by-passing the Linux Mint 17.1 (Rebecca) Host. Virtualisation VirtualBox 4.3.18_r96516 Wifi adapter TP-LINK TL-WN722N Version [ ]