new RIPE-document out

September 27th, 2012

https://www.ripe.net/ripe/docs/current-ripe-documents/ripe-563 :

Finally RIPE has decided to acept the latest proposals, which is GOOD! 🙂

Abstract:

This policy originated from the work of the Abuse Contact Management Task Force.
The task force examined the collection and maintenance of resource registration
information in the RIPE Database, including potential areas for improvement and
alternative approaches.

This policy introduces a new contact attribute named "abuse-c:”, that can be
included in inetnum, inet6num and aut-num objects.

good website

September 27th, 2012

Found an interesting website dealing with malware-analysis:

http://websiteanalystsresource.wordpress.com/

Seems like a good source for information.

internet security days

September 10th, 2012

..start tomorrow at the Phantasialand near Cologne. Too bad that
that abuse-team meeting and the meeting of the email security group
takes place simultaneously. Guess I have to throw the dice to decide where to go..

State Sponsored Malware Takes Over Mars Rover

August 10th, 2012

Interesting article here.

From the article: “Wording is purposefully crafted to generate attention.”

RIPE lost DNS-reverse zones

June 14th, 2012

Regardless of the announcement in
http://www.ripe.net/internet-coordination/news/announcements/update-regarding-the-reverse-dns-services-issues there is still a problem regarding different ipv4-reverse ranges.
Somehow RIPE lost them..:-(

Let us see when they really have fixed the problem.

MySQL-Bug

June 11th, 2012

As Heise reported, there ia a possible login-bug in MySQL. Enough trials lead to a login without a valid password. At least some distributions are vulnerable (reports from “hetzner” vserver customers).

MAAWG

June 2nd, 2012

Next week the 25th MAAWG meeting will take place in Berlin.
Let’s see what news can be learned there.

phish-run

May 25th, 2012

This morning, 10:28 a.m. a new domain got created:

Updated Date: 25-may-2012
Creation Date: 25-may-2012
Expiration Date: 25-may-2013

Same day, a few hours later:

No match for “domain”.
>>> Last update of whois database: Fri, 25 May 2012 14:37:56 UTC <<<

So much work for the spammer:

  • generate a fakeaccount at yahoo!
  • register a domain
  • generate a fakeaccount at freenet (for sending)
  • build a phish webseite and upload it
  • generate the email and send it
  • and after about 50 clicks the domain was already removed..
    money earned? .. none 🙂

    Mini Moog

    May 23rd, 2012

    I am very impressed by the emulation of the “Mini Moog” Synthesizer presented as the Goggles “Doodle” of today – including a 4-track recorder .. whow!

    I remember the times when I actually played a Mini Moog back in the 70’s 🙂

    php-bug

    May 4th, 2012

    If you run PHP in cgi-mode you are probably vulnerable to a newly found bug:
    Heise: Gefahr-durch-offene-PHP-Luecke
    Adding parameters like http://localhost/index.php?-s to an url can show the source code or even inject or run parametes in the shell.

    Until an update exists it might be wise to filter out some string-elements (like “-” without “=”)
    RewriteCond %{QUERY_STRING} ^(%2d|-)[^=]+$ [NC]
    RewriteRule ^(.*) $1? [L]