August, 2008


27
Aug 08

MITM Attack Prevention: Perspectives

Two students (Dan Wendlandt, Ethan Jackson) from carnegie mellon university have developed a system to improve the security of host fingerprint based authentication, protocols that use this type of authentication are secure web traffic(https) and secure shell (ssh), the system is explained by thier site as such:

Perspectives is a new approach to help clients securely identify Internet servers in order to avoid “man-in-the-middle” attacks. Perspectives is simple and cheap compared to existing approaches because it automatically builds a robust database of network identities using lightweight network probing by “network notaries” located in multiple vantage points across the Internet.

They’ve developed so far an ssh client based on OpenSSH and an extension for Firefox 3.


22
Aug 08

Email spam prevention techniques: sender specific forwarders

For some time now, when i would be signing up for a web service, download, weblog subscription or some other online gadget where an email address is required for sending information, i would create a temporary mail forwarder specifically for that sender.

I decided that logging into my server to create the forewarder in my database was a bit much work for something i was doing increasingly commonly, so i did what any self respecting hacker would do, i rolled my own script that can insert, remove and track forwarders, it’s reasonably secure for your average php hackjob.
Continue reading →


18
Aug 08

Rustic colour sketching experiment..

xr4 sketch small
This sketch was created using Autodesk (formerly Alias) SketchBook Pro, the entire sketch was never on paper, autodesk sbp has completely replaced paper sketching for me, it gives me professional tools, like air brushes, felt tips, ball points and a large variety of pencils in any colour I want and the touch of a pen, Im slowly getting used to the graphics tablet as a primary drawing impliment, plus im not wasting any paper this way, so its good for the environment too.

http://usa.autodesk.com/adsk/servlet/index?id=6848332&siteID=123112

I just wish there was something close to it, with an open source license.. if only i had the time.