Internet Security Systems - AlertCon(TM)

Archive Index

05/22/2013 Redirecting RF
04/09/2013 April 2013 Super Tuesday YongChuan Koh
03/27/2013 IBM X-Force 2012 Annual Trend & Risk report has released! Leslie Horacek
03/12/2013 March 2013 Super Tuesday Update Zubair Ashraf
02/12/2013 February 2013 Super Tuesday Update YongChuan Koh
01/09/2013 January 2013 Super Tuesday Update Zubair Ashraf
12/11/2012 December 2012 Microsoft Super Tuesday YongChuan Koh
11/13/2012 November 2012 Microsoft Super Tuesday Zubair Ashraf
10/09/2012 October 2012 Microsoft Super Tuesday Zubair Ashraf
09/20/2012 Key highlights in the IBM X-Force 2012 Trend & Risk Report Leslie Horacek
09/11/2012 September 2012 Microsoft Super Tuesday Zubair Ashraf
08/14/2012 August 2012 Microsoft Super Tuesday Shane Garrett
07/23/2012 What's Happening at Black hat this Year Zubair Ashraf
07/20/2012 Black Hat 2012 picks Shane Garrett
07/16/2012 Digging Deep Into The Flash Sandboxes at Black Hat USA 2012 Mark Yason and Paul Sabanal
07/10/2012 July 2012 Microsoft Super Tuesday Shane Garrett
06/12/2012 June 2012 Microsoft Super Tuesday Shane Garrett
05/09/2012 The Advanced Persistent Threat in 2012 Tom Cross
05/08/2012 May 2012 Microsoft Super Tuesday Shane Garrett
04/10/2012 April 2012 Microsoft Super Tuesday Shane Garrett
03/22/2012 Key highlights in the IBM X-Force 2011 Trend & Risk Report Leslie Horacek
03/13/2012 March 2012 Microsoft Super Tuesday Shane Garrett
02/14/2012 February 2012 Microsoft Super Tuesday Shane Garrett
02/03/2012 Remote Code Execution in PHP 5.3.9 Shane Garrett
01/26/2012 CVE-2012-0003 Exploited in the Wild Shane Garrett
01/10/2012 January 2012 Microsoft Super Tuesday Shane Garrett
12/16/2011 A Note on Critical Infrastructure Michael Montecillo
12/13/2011 December 2011 Microsoft Super Tuesday Shane Garrett
12/01/2011 Tune in to the December Blackhat Webcast Tom Cross
11/16/2011 No More Blind Spots Ory Segal
11/08/2011 November 2011 Microsoft Super Tuesday Shane Garrett
11/02/2011 DoS/DDoS tools by The Hacker Choice (THC) group adds to attack concerns Matthew Dobbs
10/11/2011 October 2011 Microsoft Super Tuesday Shane Garrett
09/30/2011 Key Findings in the IBM X-Force 2011 Trend & Risk Report Leslie Horacek
09/23/2011 Spam Volume – How the story continues during summer 2011 Ralf Iffert
09/13/2011 September 2011 Microsoft Super Tuesday Shane Garrett
08/16/2011 Our Presentation on Secure Open Wireless Networking Tom Cross
08/09/2011 August 2011 Microsoft Super Tuesday Shane Garrett
08/04/2011 Secure Open Wireless code now available! Tom Cross
08/01/2011 Secure Open Wireless in the Blackhat Arsenal Tom Cross
07/29/2011 What's up at BlackHat this year? Jon Larimer
07/28/2011 A look at Blackhat 2011 Shane Garrett
07/27/2011 Playing In The Reader X Sandbox at Black Hat USA 2011 Mark Yason and Paul Sabanal
07/15/2011 When can alerting the public about exploitation do more harm than good? Tom Cross
07/12/2011 July 2011 Microsoft Super Tuesday Shane Garrett
06/14/2011 June 2011 Microsoft Super Tuesday Shane Garrett
05/19/2011 Common Vulnerability Reporting Format (CVRF) is announced! Tom Cross
05/10/2011 May 2011 Microsoft Super Tuesday Shane Garrett
05/03/2011 Another wave of ZIP attachment spam Ralf Iffert
05/02/2011 SQL Slammer Gradually Returns... Tom Cross
04/12/2011 April 2011 Microsoft Super Tuesday Shane Garrett
04/01/2011 IBM X-Force 2010 Trend Report launched! Leslie Horacek
04/01/2011 SQL Slammer’s mysterious disappearance Tom Cross
03/31/2011 Analyzing a Mass SQL Injection Attack - Lizamoon John Kuhn
03/25/2011 Monitoring SecurID Authentication Failures Tom Cross
03/21/2011 The Rustock Takedown and Global Spam Volumes Ralf Iffert and Tom Cross
03/21/2011 Advanced Persistent Threat: An Iterative Approach Tom Cross
03/08/2011 March 2011 Microsoft Super Tuesday Shane Garrett
03/03/2011 Examining the recent Android malware Jon Larimer
02/08/2011 February 2011 Microsoft Super Tuesday Shane Garrett
02/07/2011 ShmooCon 2011 presentation: USB autorun attacks against Linux Jon Larimer
01/13/2011 Spam bots back from the holiday season Ralf Iffert
01/11/2011 January 2011 Microsoft Super Tuesday Shane Garrett
01/10/2011 Blackhat DC, Shmoocon, and GNOME evince Jon Larimer
12/22/2010 Virtualization Webcast at SANS Tom Cross
12/14/2010 December 2010 Microsoft Super Tuesday Shane Garrett
12/10/2010 IANA, ARIN, and the IPv4 run-out (Series - Part IV of IV) Michael H. Warfield
12/08/2010 IANA, ARIN, and the IPv4 run-out (Series - Part III of IV) Michael H. Warfield
12/06/2010 IANA, ARIN, and the IPv4 run-out (Series - Part II of IV) Michael H. Warfield
12/01/2010 IANA, ARIN, and the IPv4 run-out  (Series - part I of IV) Michael H. Warfield
11/12/2010 On password protected free wifi... Takehiro Takahashi and Tom Cross
11/09/2010 November 2010 Microsoft Super Tuesday Thoughts Shane Garrett
11/09/2010 Stuxnet webcast at SANS Jon Larimer
10/27/2010 A new solution to wireless security issues Tom Cross and Takehiro Takahashi
10/20/2010 X-Force vulnerabilities patched in October Shane Garrett
10/12/2010 Microsoft Super-Tuesday Thoughts Shane Garrett
10/05/2010 National Cyber Security Awareness Month John Kuhn
09/15/2010 iPhone Jailbreak Type2 Charstring Vulnerability from August Takehiro Takahashi
08/30/2010 The Monday After The SQL Storm John Kuhn
08/30/2010 Protecting Against Remote DLL Preloading Vulnerabilities Shane Garrett and David Means
08/28/2010 Mid-Year 2010 X-Force Trend and Risk Report - Update to Unpatched Vulnerabilities Chart Tom Cross
08/24/2010 A new wave of ZIP malware spam Jon Larimer and Ralf Iffert
08/19/2010 MS10-046 .lnk vulnerability? We have that... John Kuhn
07/30/2010 Playing With Tabnabbing Michael Montecillo
07/26/2010 Follow us at Blackhat on Twitter! IBM
07/21/2010 Blackhat USA for Mobile Researchers Takehiro Takahashi
07/21/2010 What I'm seeing at Blackhat Jon Larimer
07/21/2010 Understanding the Low Fragmentation Heap at Blackhat Chris Valasek
07/20/2010 Unauthorized Internet Wiretapping at Blackhat USA 2010 Tom Cross
07/12/2010 Review of the Java Web Start Jailbreak Vulnerability By Mike Montecillo and Craig Billado
07/09/2010 Anonymity on the Internet… Good or Bad? Nick Bradley
06/01/2010

SANS Webcast – Anatomy of the Advanced Persistent Threat

Jon Larimer
05/03/2010 The Aftermath of doc.pdf, statistics, payload, and spam John Kuhn and Matthew De Carteret
04/28/2010 Don’t open that doc.pdf, it’s got pwnage inside! Jon Larimer and John Kuhn
03/29/2010 PAM 2.0 - Future of the Protocol Analysis Module Terry Nelms
03/09/2010

Who’s the hardest working researcher of all time?  Of 2009?

Scott Moore
03/05/2010 Creating News for Blackhat SEO Jon Larimer
02/25/2010 Key Findings in the 2009 X-Force Trend and Risk Report Leslie Horacek and Michelle Alvarez
02/19/2010 Frequency X has been nominated for an award! Tom Cross
02/18/2010 Thanks for the malware sample! John Kuhn and Jon Larimer
02/08/2010 My Blackhat DC Paper, Slides, and Video are available Tom Cross
01/15/2010 The Google Attacks Tom Cross
01/14/2010 My talk at the upcoming Blackhat DC conference Tom Cross
12/18/2009 A New Years Resolution - Find out how your corporate domain name is managed. Tom Cross
12/17/2009 Reflecting on NTLM Reflection Takehiro Takahashi
12/09/2009 Blackhat Demo Explained Chris Valasek
11/25/2009 No Thanks Koobface Jon Larimer
11/23/2009 Internet Explorer CSS 0day likely to take off Robert Freeman
11/12/2009 Stealing Cookies with SSL Renegotiation Tom Cross
11/06/2009 ...and while we're talking about MITM... Tom Cross
11/06/2009 You can relax about the SSL break, mostly. Tom Cross
10/19/2009 Gumblar Reloaded John Kuhn and Ryan McNulty with a little help from Holly Stewart
10/09/2009 Yes, Phishing is Back Ralf Iffert and Holly Stewart
09/09/2009 SockStress Vulnerabilities Patched Tom Cross
09/09/2009 SMB 0-Day Chris Valasek
08/28/2009 Key findings in the Mid-Year Trend and Risk Report Holly Stewart
08/12/2009 Challenges With The ISC Bind Vulnerability Daniel Hanley, Takehiro Takahashi, and David Gibson
07/28/2009 Recent Microsoft Collaboration Kris Lamb
07/28/2009 Required Reading for our Blackhat Talk John McDonald
07/20/2009 A second Blackhat '09 talk Chris Valasek
07/17/2009 Upcoming Blackhat '09 Talk Mark Dowd
06/26/2009 Spam & Phishing, A Reflection Of The Times Dan Holden
06/12/2009 Adobe Vulnerabilities Mark Dowd
06/09/2009 A VB Runtime Bug and Critical Section Lock Exploitation Robert Freeman
06/08/2009 Conficker SQL Injection connection or coincidence? Jennifer Szkatulski, John Kuhn, and Ryan McNulty
05/08/2009 SQL Injection Lessons from X-Force Emergency Response Service Investigations Harlan Carvey
05/05/2009 No Sleep for Conficker on Cinco de Mayo Holly Stewart
05/04/2009 Image spam - reborn and trying to rejuvinate YOUR health! Ralf Iffert & Holly Stewart
04/09/2009 Updated Stats for Conficker.C Hollly Stewart
04/02/2009 Counting Confickers Holly Stewart
04/01/2009 Conficker 'round the world John Kuhn
04/01/2009 April Fools in July? Holly Stewart
03/30/2009 Who is watching your Conficker? Holly Stewart
03/25/2009 Why Chicks Dig IE8 Mark Dowd
03/21/2009 Blinkered Thoughts on 'Smart Grid' Security Gunter Ollmann
03/19/2009 Cyberheists & Keyloggers Gunter Ollmann
03/17/2009 Adobe JBIG2... going big? John Kuhn and Holly Stewart
03/06/2009 RSA 2009 - Security Ergonomics & back-office anti-fraud protection techniques Gunter Ollmann
02/23/2009 Adobe Reader Woes, Again Jennifer Szkatulski, John Kuhn, and Holly Stewart
02/17/2009 Top-10 Vulnerability Discoverers of All Time (as well as 2008) - Who's in Pole Position? Gunter Ollmann
02/12/2009 Anti-virus Vendors Succumbing to SQL Injection Gunter Ollmann
02/02/2009 2008 Annual Security Trend and Risk Report Now Available - and a Great Read too! Gunter Ollmann
01/30/2009 Preview of the 2008 X-Force Trend and Risk Report Holly Stewart
01/29/2009 Thoughts on Conficker Tom Cross
01/26/2009 Social Network Denial of Service (SDoS)? Gunter Ollmann
01/20/2009 Largest Data Breach So Far? Heartland Payment Systems Gunter Ollmann
01/09/2009 Week of (everyone else's) Security Predictions 2009 - Day 5 Gunter Ollmann
01/08/2009 Week of (everyone else's) Security Predictions 2009 - Day 4 Gunter Ollmann
01/07/2009 Week of (everyone else's) Security Predictions 2009 - Day 3 Gunter Ollmann
01/06/2009 Week of (everyone else's) Security Predictions 2009 - Day 2 Gunter Ollmann
01/05/2009 Week of (everyone else’s) Security Predictions 2009 – Day 1 Gunter Ollmann
12/15/2008 Going Nuclear - Cyber-threats for Nuclear Power Plants Gunter Ollmann
12/12/2008 Apparently Hackers Have Been Helping to Destroy the Amazon Rainforest Gunter Ollmann
12/05/2008 Spam - Back Up to 50% Capacity Carsten Hagemann
12/04/2008 Infected Advertising - Wrongful Delegation of Malware Responsibility Gunter Ollmann
12/01/2008 Making the Web more secure and a bit greener too? Gunter Ollmann
11/26/2008

What You May Have Missed About CVE-2008-0017: A Firefox NULL Dereference Bug

Justin Schuh
11/25/2008 McColo Takedown: Changes in International Spam Distribution and Asprox Botnet Activity Ralf Iffert, John Kuhn, and Holly Stewart
11/24/2008 From Virus to Parasite – The Parasitic Era of Malware Gunter Ollmann
11/16/2008 CSI 2008 – Web Security, Cloud Computing and the Man-in-the-browser Gunter Ollmann
11/10/2008 The Scoop on the X-Force TrendMicro Advisories David Dewey
11/05/2008 Stopping PDF Malware At The Network John Kuhn
11/04/2008 How do you continue to do business with malware infected customers? Gunter Ollmann
10/29/2008 Beating the Man-in-the-browser with a ZTIC Gunter Ollmann
10/27/2008 Tougher times for exploit developers, but more at risk Gunter Ollmann
10/23/2008 Microsoft publishes great technical information Tom Cross
10/01/2008 Conference Time – OWASP and VB2008 Gunter Ollmann
09/22/2008 Disgruntled Job Losers and their Insider Threat Gunter Ollmann
09/22/2008 Has your webmail been hacked? Andi Baritchi
09/19/2008 Protecting your Webmail - Updated (Twice) Tom Cross
09/08/2008 Recovering (someone else’s) Email Password Gunter Ollmann
09/02/2008 Internal Security Expertise - Have you got the balance right? Gunter Ollmann
08/29/2008 Hackers Prepare UK Supermarket Sweep Gunter Ollmann
08/28/2008 OWASP 2008 - “Multidisciplinary Bank Attacks” Gunter Ollmann
08/10/2008 Web Browser Incompatibilities Gunter Ollmann
08/04/2008 Blackhat & DefCon - Las Vegas 2008 Gunter Ollmann
08/01/2008 A Quick Note on Sun's SNMPXDMI Agent
Jamie Licitra
07/28/2008 Mid-Year Threat Report Holly Stewart
07/25/2008 Meaningless Malware Counting? Gunter Ollmann
07/25/2008 Responding to the DNS vulnerability and attacks Tom Cross
07/22/2008 Kaminsky DNS attack leaked Tom Cross
07/18/2008 Cyberspying Gunter Ollmann
07/14/2008 More on DNS Cache Poisoning and Network Address Translation Tom Cross
07/14/2008 Strategic Security – Cloud-based MSS Gunter Ollmann
07/10/2008 (UPDATED) DNS Cache Poisoning and Network Address Translation Tom Cross
07/07/2008 Trojans on the up Gunter Ollmann
07/02/2008 637 million Excuses Gunter Ollmann
07/01/2008 637 million Users Vulnerable to Attack Gunter Ollmann
06/12/2008 Strategic Security – Embedding it Gunter Ollmann
06/11/2008 CanSecWest Follow-Up: MJPEG Vulnerability Mark Dowd
06/10/2008 Why you must run Windows Update after every component installation Chris Valasek
06/09/2008 DIY Credit Card - Chips and Smart Cards Gunter Ollmann
06/03/2008 DIY Credit Cards Gunter Ollmann
05/28/2008 Global Innovation Outlook - Security and Society Gunter Ollmann
04/29/2008 I'm Feeling Lucky Robert Freeman
04/24/2008 Are you Feeling Lucky? Gunter Ollmann
04/23/2008 More on Automatic Patch Based Exploit Generation Tom Cross
04/22/2008 "Automatic Patch-Based Exploit Generation is Possible" - So say we all. Gunter Ollmann
04/14/2008 CAPTCHA's and Mechanical Turks Gunter Ollmann
04/11/2008 Flash Mark Dowd
04/01/2008 A Second-order of XSS Gunter Ollmann
03/29/2008 The Cost of Networking @ Blackhat Gunter Ollmann
03/28/2008 Apple Crumble @ Blackhat Gunter Ollmann
03/25/2008 Excel exploit (MS08-014) in the wild Robert Freeman
03/16/2008 Security Ergonomics Gunter Ollmann
03/14/2008 Xensploit: A recipe for attention Kevin Skapinetz
03/13/2008 Mass Attack - March Madness? Gunter Ollmann
02/29/2008 Timely Disclosure? Mark Dowd
02/29/2008 Chip and PIN Tampering Gunter Ollmann
02/25/2008 Evolving Beyond CAPTCHA Gunter Ollmann
02/12/2008 Remotely Exploitable Trends in 2007 Gunter Ollmann
02/11/2008 The Vulnerability Disclosure Rate in 2007 Gunter Ollmann
02/08/2008 2007 X-Force Report Preview - Malcode Trends Kris Lamb
02/07/2008 2007 X-Force Report Preview - Web Content Trends Kris Lamb
02/06/2008 2007 X-Force Report Preview - Spam and Phishing Trends Kris Lamb
02/05/2008 2007 X-Force Report Preview - Browser Exploitation Trends Kris Lamb
02/05/2008 2007 X-Force Report Preview - Vulnerability Trends Kris Lamb
01/17/2008 Protection Problems with MS08-001 Holly Stewart
01/08/2008 Vulnerabilities in MS TCP/IP - MS08-001 Chris Valasek
11/30/2007 Phishers test the water with shorter hooks Ralf Iffert
11/26/2007 Do Not Call List—R.I.P. Dan Ingevaldson
11/20/2007 Placing a Value on Passwords Gunter Ollmann
11/12/2007 Psst... wanna buy some credit cards? Gunter Ollmann
11/09/2007 Jihad 3.0 Analysis Mark Yason and Chris Valasek
10/23/2007 PDF Spam 2.0 Ralf Iffert
10/22/2007 XSOX.NAME and Proxy Bots Gunter Ollmann
10/19/2007 Heard any good spam lately? Ralf Iffert
10/16/2007 RFID Worms - Fact or Fiction? Gunter Ollmann
10/15/2007 Anti-malware’s backward brother Gunter Ollmann
10/04/2007 There's a Storm Coming Will Irace
10/01/2007 Phishing Tsunami Passes Gunter Ollmann
09/21/2007 Virtualization and Security Kris Lamb
09/20/2007 Charitable Donations on Your Behalf Gunter Ollmann
09/17/2007 The Low and Slow threat Dan Holden
09/17/2007 Phishing on the Fly Gunter Ollmann
09/12/2007 Ultimate Data Storage - Microfiche? Gunter Ollmann
08/30/2007 The Short Path to Deniability Gunter Ollmann
08/22/2007 Who's funding Pirate Bay this week? Gunter Ollmann
08/20/2007 The End of One-man-show Phishing Attacks? Gunter Ollmann
08/19/2007 Old Threats Never Die Gunter Ollmann
08/15/2007 International Money Mule Recruitment – Part II - The Recruitment Site Gunter Ollmann
08/15/2007 CLPWN Gunter Ollmann
08/14/2007 International Money Mule Recruitment – Part I – The FAQ Gunter Ollmann
08/10/2007 Cisco IOS IPv6 Routing Header Information Leak Tom Cross
08/10/2007 Demand More Jon Amato
08/08/2007 Social Network Hacking Gunter Ollmann
08/07/2007 Black Hat 2007 Jean Paul Ballerini
08/04/2007 Vulnerability Brokers Gunter Ollmann
07/31/2007 The Mule Trade Gunter Ollmann
07/26/2007 Behavioral Detection and ATM Theft Mark Vincent Yason
07/24/2007 Top-10 Vulnerable Vendors Gunter Ollmann
07/17/2007 PDF: The new spam frontier? Ralf Iffert
07/11/2007 Phishing under the Microscope Gunter Ollmann
07/04/2007 Heisenberg Uncertainty Gunter Ollmann
07/01/2007 Firewall Spring Cleaning Gunter Ollmann
06/28/2007 Spear Phishing and Whaling Gunter Ollmann
06/24/2007 Web Browser Exploitation Gunter Ollmann
06/20/2007 Reflecting on an “Italian Job” Robert Freeman
06/18/2007 Busy Week for Phishing Kits Gunter Ollmann
06/15/2007 SCH and Yahoo! Webcam ActiveX control vulnerabilities Mark Vincent Yason
06/13/2007 Disclosure vs. Ethics Gunter Ollmann
06/08/2007 Intellectual Weapons Tom Cross
06/06/2007 Phishing Kits Classified Gunter Ollmann
05/30/2007 Who do you trust? Dan Holden
05/29/2007 Counting Vulnerabilities Gunter Ollmann
05/24/2007 A Slowdown in Vulnerability Disclosure? Gunter Ollmann
05/23/2007 The Vishing Guide
Gunter Ollmann
05/23/2007 x-Morphic Attack Engines
Gunter Ollmann
05/11/2007 X-Force Protection Engines Dan Holden
03/19/2007 Microsoft Vista Vulnerability Ranking Gunter Ollmann
03/08/2007 No new security patches from Microsoft for March Tom Cross
02/21/2007 Stopping Botnet C&C on the Wire Gunter Ollmann
02/19/2007 Targeted or Personalized Attacks?
Gunter Ollmann
02/13/2007 February Microsoft Updates Tom Cross
01/30/2007 ProfileWatcher on MySpace
Mark Vincent Yason
01/14/2007 Violent Crime, CSI and Vulnerability Disclosure Gunter Ollmann
01/09/2007 More on Key Management Tom Cross
01/09/2007 January Microsoft Updates Tom Cross
01/08/2007 Uptick in QQPlayer Exploit in the Wild Robert Freeman
01/05/2007 Thoughts on Key Management Robert Freeman
01/05/2007 Some Interesting Crypto Morsels Tom Cross
01/04/2007 Serious PDF Cross Site Scripting Vulnerability Tom Cross
01/02/2007 The End of 2006 - A Record 7247 Vulnerabilities! Gunter Ollmann
12/18/2006 7000 new vulnerabilities so far Gunter Ollmann
12/14/2006 From Botnet to Malnet Gunter Ollmann
12/13/2006 10 Years of Flash! Gunter Ollmann
12/12/2006 December Microsoft Patches Tom Cross
12/11/2006 HTML Tag used to Obfuscate Exploit Robert Freeman
11/14/2006 November Microsoft Patches Tom Cross
11/10/2006 Google protecting the unwary Gunter Ollmann
11/03/2006 New IE 0day Identified Robert Freeman
11/02/2006 Software Developers Targeted by Web Exploit Robert Freeman
10/26/2006 The Eavesdropper's Dilemma Tom Cross
10/24/2006 A Surge of Redirection to a known IE ActiveX Exploit Robert Freeman
10/19/2006 Browser Wars - Part 42? Gunter Ollmann
10/18/2006 Webcams and Security - A match made in ...? Gunter Ollmann
10/12/2006 Fuzzing Lays at the Heart of 2006 Vulnerability Increases Gunter Ollmann
10/03/2006 Vulnerability Avalanche Gunter Ollmann

Comments or opinions expressed on this Weblog are the opinions of the authors alone. They are not necessarily reviewed in advance by anyone but the individual authors, and neither IBM Internet Security Systems nor any other party necessarily agrees with them. The views expressed by outside contributors and links to outside websites do not represent the views of IBM Internet Security Systems, its management or employees. All content on this Weblog has been made available on an “as-is” basis, and IBM Internet Security Systems shall not be liable for any direct or indirect damages arising out of use of this Weblog.