ZDNet Must Read:
Microsoft confirms 'detailed' Windows 7 exploit
Microsoft has issued a security advisory to acknowledge a crippling denial-of-service flaw affecting its newest operating systems -- Windows 7 and Windows Server 2008 R2.... Continued »
Category: Microsoft Blue Hat v7
August 9th, 2008
Black Hat Las Vegas Day 2
Again, sorry for the late updates. Vegas is the kind of place that demands a lot of a person. Too many parties make it difficult to find time to blog on the conference. Pictures of the even are a bit sparse, due to consistently forgetting to bring my camera, but I will post them shortly.
Day 2 began a bit rough for me, but I forced myself down to catch Shawn Moyer and Nathan Hamiel’s talk, “Satan Is On My Friends List”. The talk was really solid, and focused on attacking social networking sites, such as MySpace, Adult Friend Finder, and LinkedIn. The pair pointed out numerous flaws with these sites, such as impersonation, theft of sensitive data (pics etc.), arbitrary code execution (through various plug-in applications).
July 15th, 2008
Finding the name behind the GMail address
Ah, this is a fun little trick. I’m not sure if it represents a vulnerability, but certainly I expect Google will try to get rid of this feature. The SecuriTeam blog has reported that it is possible to expose the full name of the user who registered a GMail account. This is, of course, contingent on the fact that the person who registered the GMail account didn’t use a fake first and last name, but still, an interesting trick.
The reason this vulnerability exists is due to the strong tie-ins between GMail and all of Google’s other services, such as Google Calendar, Blogger, and Google Code AND the strong desire for Google Apps to be able to share data with people. This isn’t the first time, the second time, or the last time the strong tie-ins have produced interesting results, see my post on Billy Rios’s Google Code exploit, Billy’s taking ownership (pwnership) of content attacks against Google Spreadsheets, Billy and I stealing documents from Google Docs, and see my talk at Black Hat for more.
The steps to accomplish this are as follows:
- Sign up for Google Calendar
- Go to the ’share this calendar’ tab
- Enter the email address in the ‘person’ box
- Click ‘add person’ and ’save’
- When you return to this screen you will see the first and last name along with the gmail address
July 7th, 2008
AVG changes its stance on LinkScanner
A few days ago I wrote a story about AVG’s LinkScanner causing a massive amount of additional traffic on the net in the name of protecting customers… yeah. Well, here’s a quote from the original article to give some background:
Apparently AVG is spamming the Internet with traffic that looks to be coming from Internet Explorer. AVG software pre-crawls search results to try to protect users, but uses a user agent that makes the software appear to be Internet Explorer. This pre-crawling is flooding websites with meaningless traffic (Slashdot claims it is up to 6% of their traffic, which given Slashdot’s load is CONSIDERABLE). More importantly, they’re apparently aware of this bad behavior and are changing their user agent to avoid filters.
From that story, I posted a poll that asked, “Do you think that AVG’s LinkScanner should be added to the badware list?” A respectable 1,065 people voted on this, and a resounding 77% of people believed that AVG’s LinkScanner should be added to the badware list.
May 6th, 2008
Can I interest you in a glass of Berry Blue Kool-Aid?: A recap of Microsoft Blue Hat v7
Hey all,
I was fortunate enough to be invited to attend Microsoft Blue Hat v 7 as I had some research that Microsoft was interested in bringing me in to talk about. Microsoft got to have co-worker and fellow researcher Rob Carter and I in to talk to product security teams about some of the things we’d found, and we got a free pass to an invite only conference that had some great talks.
Microsoft also asked me to write a guest blog on their Blue Hat site, which I was happy to do. Good friends and fellow bloggers Ryan Naraine and Rob McMillan gave me some good natured ribbing about why I got to go, and I returned the favor by saying Microsoft gave me an “exclusive” look at Blue Hat. It wasn’t really the way it went down, but it was more fun to poke some fun at the guys, so I thank Microsoft for letting me keep that in. In fact, Microsoft didn’t edit my posting at all, except to make a couple grammatical changes, so that was much appreciated. It was a very interesting trip, and I got to see several great talks and interview a few interesting people.
One thing you’ll see coming up soon is an interview I did with the guys who created DEP and ASLR, so keep your eyes open for that.
I’ve also included a gallery of pictures that includes shots of the conference, and some funny ones from the IOActive Limo Party… thanks to Josh Pennell and all the IOActive crew for putting that on, tons of fun.
-Nate

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.
SponsoredWhite Papers, Webcasts, and Downloads
- Building the Virtualized Enterprise with VMware Iinfrastructure VMware VMware virtualization software has been adopted by over 120,000 enterprise ... Download Now
- VMware Infrastructure: A Guide to Bottom-Line Benefits VMware Frustrated by the costs of maintain ever larger data centers?or building ... Download Now
- The Impact of Virtualization Software on Operating Environments VMware Today's use of virtualization technology allows IT professionals to ... Download Now
Recent Entries
- Opera patches ‘extremely severe’ security hole
- Exploit published for critical IE 7 zero-day flaw
- Inside the Google Chrome OS security model
- Microsoft finds security hole in Google Chrome Frame
- Mozilla locks out rogue Firefox add-ons
Blogs From Our Sponsors
Most Popular Posts
- Microsoft confirms 'detailed' Windows 7 exploit
- Thousands of web sites compromised, redirect to scareware
- Windows 7's default UAC bypassed by 8 out of 10 malware samples
- Mac OS X mega patch covers 58 security vulnerabilities
- Which antivirus is best at removing malware?
- Microsoft patches Windows worm holes, drive-by download flaws
Top Rated
- Facebook password-reset spam is Bredolab botnet attack+46 votes
- Microsoft confirms 'detailed' Windows 7 exploit+43 votes
- Thousands of web sites compromised, redirect to scareware+43 votes
- Firefox hit by multiple drive-by download flaws+41 votes
- Which antivirus is best at removing malware?+40 votes
- iHacked: jailbroken iPhones compromised, $5 ransom demanded+32 votes
- New LoroBot ransomware encrypts files, demands $100 for decryption+28 votes
- Mac OS X mega patch covers 58 security vulnerabilities+26 votes
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer>>
- Learn more about tools to grow your business
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Save time with the UPS Business Essentials Guide
- Reduce risk. Reduce complexity. Increase reliability.
-
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
- Learn more >>
Archives
Favorite Links
ZDNet Blogs
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Dev Connection
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- Irregular Enterprise
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- On Sustainability
- Rational Rants
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Social CRM: The Conversation
- Software & Services Safari
- Software as Services
- Storage Bits
- Team Think
- Tech Broiler
- Technology and the Global Supply Chain
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
White Papers, Webcasts, and Downloads
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Companies have rapidly adopted server virtualization over the past few ... Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- The True Costs of Virtual Server Solutions VMware In an economic environment that is repeatedly heralding the message "do ... Download Now
-
-
Smart Tech
Expert advice on innovations in healthcare and the green technologies that make it happen.
Find out more
-
Smart Business
Discussion and advice on management issues that revolve around making your world smarter and more useful.
More Smart Advice
-
Smart People
The best and worst moves in the management and strategy trenches.
Learn More






