Changes to SMS Delivery and How it Effects MFA and Phishing, (Tue, Oct 17th)

Spam and phishing SMS messages (sometimes called “smishing”) have been problematic in recent years. These messages often bypass security controls and are more challenging to identify as malicious by users. Moreover, they can be just simply annoying.

Continue reading Changes to SMS Delivery and How it Effects MFA and Phishing, (Tue, Oct 17th)→

Posted in Uncategorized

Domain Name Used as Password Captured by DShield Sensor, (Sun, Oct 15th)

While reviewing my DShield honeypot logs, I noticed for the first time something strange in my list of Top Username &#;x26; Password where&#;xc2;&#;xa0;several domain name were use as password. Initially,&#;xc2;&#;xa0;I was under the impression this might be&#;xc2;&#;xa0;a parsing error by Logstash and&#;xc2;&#;xa0;decided to review the raw logs to make sure it was parsed correctly to confirm data integrity. Since username and passwords isn&#;x26;#;39;t something submitted to DShield, I reviewed my own raw logs to confirm the data was accurate and reviewed the&#;xc2;&#;xa0;capture rate of username/password combination&#;xc2;&#;xa0;for the past few weeks:

Continue reading Domain Name Used as Password Captured by DShield Sensor, (Sun, Oct 15th)→

Posted in Uncategorized

What’s Normal: MAC Addresses, (Fri, Oct 13th)

In this installment of “What&#;x26;#;39;s Normal”, I want to discuss MAC addresses. MAC addresses are used to identify devices on ethernet networks. They are six bytes in length and typically expressed in hexadecimal, separated by a colon or a dash. MAC addresses identify network interfaces on the local network. They must be locally unique and are, to some extent globally unique.

Continue reading What’s Normal: MAC Addresses, (Fri, Oct 13th)→

Posted in Uncategorized