Information Security Short Takes
You're new here, aren't you?
Click Connect with Facebook to join NetworkedBlogs. NetworkedBlogs is a community of bloggers and blog lovers. Join the fun, add your blog, and connect with others who read and write about subjects you like.
Tutorial - Breaking Weak Encryption With Excel
The importance of a good encryption algorithm is essential to functional security. And yet there are a lot of misguided initiatives to use an 'internal', 'trusted' and 'secret' algorithm. Obscurity IS NOT Security and an algorithm that hasn't passed external scrutiny may be fundamentally flawed. If you go down that road you may even find your encryptions hacked by non-programmers.Here is a tutorial on how easy it is to crack an encryption that is not properly designed. For this tutorial, We are going to work with a really simple and weak algorithm - XECryption.Here is a narrative summary of the algorithm:The password the user chose is
GenApple - First Glance at the First Information Brokerage
Internet has become a transfer medium for a lot of new business models, some of which have failed and others which are thriving. In this environment, there is new service called GenApple, which boasts to be the 'first information brokerage in the world'
How To - Malicious Web SIte Analysis Environment
There are numerous sites and web-server side scripts which perform malicious attacks or simply unpleasant problems to their visitors.The latest one that gained prominence, is the although not really causing much harm is the "Want 2 C Something Hot?". It is an elegant XSS hidden which just shares itself on the facebook profile of the visitor.
HTTPS Data Exposure - GET vs POST
Here is a quick chart showing the data exposure when considering GET vs POST and also HTTP vs HTTPS.URL arguments refer to arguments in the URL for GET or POST (e.g. foo.com?arg1=something).Body arguments refer to data communicated via P
Not enough data.
Calculated for blogs with 20+ followers.
- BlogInfoSec.com
security, information security, security management
- Clark Thought Leadership
Information Technology, Information Security, African American
- IT & Risk: A Security Assurance Blog
Information Security, Application Security, Information Technology
- RiskAnalys.is
risk, risk management, information security
- SecTechno
Network Security, Information Security, Hacking
Questions? contact: networkedblogs@ninua.com
Copyright (C) 2008, Ninua, Inc.