Grumpy Security Guy

I’ve suffered the tortures of the damned

Grumpy Security Guy header image 4

Entries from June 2008

The Business Case for WAFs + Testing

June 19th, 2008 ·

Here is a real world story about a customer of ours, this was a few years ago and was one of the key points in bringing the F5/Mod_security/WhiteHat integrated solution to market.
This customer had a massive application written in ASP classic. Since it was in ASP classic it had massive numbers of SQLi vulnerabilities. Everything [...]

[Read more →]

Tags: Security

When ISPs Attack!

June 19th, 2008 ·

Here is a scary story about a company, Nebuad (no link juice for you!) that performs a MITM attack all in the name of better ads. Now sniffing to get better data on your customers has been around for a while. In fact I worked at a company that did this as part of our [...]

[Read more →]

Tags: Security · web site security

Dude Don’t Hack My Coffee

June 17th, 2008 ·

As someone trying to get off the coffee train I find the recent reports of vulnerabilities in network connected coffee machines somewhat amusing. It seems some guy that has $2,900 to spend on a coffee maker(!!) also has the skillz to find a buffer overflow in it.
This type of thing is only going to increase [...]

[Read more →]

Tags: Security