SSL 2.0 turns 30 this Sunday… Perhaps the time has come to let it die?, (Fri, Feb 7th)

The SSL 2.0 protocol was originally published back in February of 1995[1], and although it was quickly found to have significant security weaknesses, and a more secure alternative was released only a year later[2], it still received a fairly wide adoption.

Continue reading SSL 2.0 turns 30 this Sunday… Perhaps the time has come to let it die?, (Fri, Feb 7th)

Posted in Uncategorized

The Unbreakable Multi-Layer Anti-Debugging System, (Thu, Feb 6th)

The title of this diary is based on the string I found in a malicious Python script that implements many anti-debugging techniques. If some were common, others were interesting and demonstrated how low-level high-level languages like Python can access operating system information. Let’s review some of them!

Continue reading The Unbreakable Multi-Layer Anti-Debugging System, (Thu, Feb 6th)

Posted in Uncategorized

Phishing via “com-” prefix domains, (Wed, Feb 5th)

Phishing is always a “whack the mole” like game. Attackers come up with new ways to fool victims. Security tools are often a step behind. Messages claiming to collect unpaid tolls are one current common theme among phishing (smishing?) messages. I just received another one today:

Continue reading Phishing via “com-” prefix domains, (Wed, Feb 5th)

Posted in Uncategorized