I am a hacker and you are afraid and that makes you more dangerous than I ever could be.
Matasano Chargen » And Now For A Few Words About HP’s “Scrawlr”
Topic: Miscellaneous
4:54 pm EDT, Jun 26, 2008
Matasano gives some love, which is nice.
Some of my favorite reads (there are others) have recently written about about Scrawlr and some of what I have read has been critical. Critical enough? Depending on your level of pedantry with respect to webapp security and/or free software, probably not.
Stop that. Right now. Overlook the limitations of the tool that was released, realize that this is a closely targeted thing designed to help alleviate a specific problem. Go back and think a little harder about what is going on and why this is actually A Good Thing(tm).
[snip]
The scanner is built to look for things being indexed by search engines. If those sites are fixed, 99.999% of the problem should go away.
Trying to compare Scrawlr to a full blown SQL Injection scanning tool is like comparing a letter opener to a Swiss Army Knife. Sure, you can do other things with a letter opener (and some of you probably want to slit my throat for that simile. That’s fine, use the knife) —- but its stated purpose is to open letters.
The feedback we've been getting from developers has been "Thanks for the tool, I didn't understand [other tool]/couldn't make it work." Not surprising. These are people 5 years behind the security curve, with only a passing understanding of SQL injection and still believing XSS is all alert boxes and cookie theft. You average classic ASP dev can no more use Burp than my mom can use a methane digester. In both cases the fundamental concept of what the tool does is lost on the end user.
The feedback I've gotten from security folks is "why isn't this WI Lite. I'm sick of paying you guys $30k a year." Well, not exactly, but the subtext is there. :-)
Introduction Scrawlr: a free Crawler + SQL Injector tool
Topic: Miscellaneous
5:48 pm EDT, Jun 24, 2008
In response to all the Mass SQL Injection attacks this year, Microsoft approached HP and the Web Security Research Group (formerly SPI Labs) for assistance. While there was nothing they could patch, Microsoft wanted to provide tools to help developers find and fix these issues. After a month of development HP created Scrawlr.
Scrawlr (short for SQL Injector and Crawler) is a free tool that will crawl a website while simultaneously analyzing the parameters of each individual web page for SQL Injection vulnerabilities. Scrawlr was designed specifically to help protect against these mass injection attack which are using Google queries to find older web applications and automatically injection them. As such, Scrawlr crawls a websites using the same techniques as a search engine: it doesn’t keep state, or submit forms, or execute JavaScript or Flash. This Scrawl is finding and auditing the pages that would have been indexed by the search engines.
To reduce false positives Scrawlr provides proof of the vulnerability results by displaying the type of backend database in use and a list of available table names. There is no denying you have SQL Injection when I can show you table names!
So, last week I was at HP Software Universe. With the Practical Software Quality and Testing conference, the SANs web security summit, HPSU marked my 3rd trip to vegas in 6 weeks and my 5th business trip in 7 weeks. Needless to say after yet another week in Vegas I was absolutely exhausted.
Only then I got word that I needed to take a day trip straight from Vegas to Seattle on Friday to meet with an extra special customer. They were doing an internal security conference and wanted me to speak. So, I mustered up, flew out of Vegas at 8am, spent the day with the customer, got some dinner with them, went to my hotel, crashed, and flew out first thing the next morning. All having been in Seattle for less than 24 hours.
And then the calls and texts began. "Why didn't you call me?" "Billy, where's the love?" "WTF man?"
First of all, damn you guys have crazy spies. I specially didn't tell anyone about my trip so avoid this very thing. Second, to my Seattle Homies, I'm truly sorry I didn't hang out with you all or let you know I was coming. Travel's been kicking my ass and as much as I wanted to go to Queen Sheba and hang at Public N3rd Area, I would have been poor company. I should be back soon and can make it all up to you all, [ducks pillow], serious I promise [throws pillow].
So to celebrate the release of Firefox 3 I bring you your (old news) moment of Zen.
2006? How did I not know about this before? Come on IE8, your Acid2 compliance is getting better but your super model compliance is completely unacceptable. A sweaty Ballmer is as unsexy as a totally broken implementation of the box model...
Of course, a search for "sexy firefox" returned this not safe for work link of topless Firefox anime (never thought I'd string those words together), as the first link no less.
As such, I've decided to deduct another point from the entire country of Japan, making the new score 1 win and 2 losses.
The 17-year-old was the star of Nickelodeon's "Zoey 101," a sitcom about prep school friends, and is the younger sister of pop star Britney Spears. The Spears family announced in December that Jamie Lynn was pregnant. The father is Casey Aldridge, a pipe-layer from Liberty, Mississippi. The couple is not married but announced an engagement several months ago.
A pipe layer? HA! Someone at CNN has a good sense of humor. :-)
Sixth severed foot surfaces off Canadian coast - CNN.com
Topic: Miscellaneous
8:06 pm EDT, Jun 18, 2008
A severed foot -- the sixth in 11 months -- washed up on the shore of a Canadian island on Wednesday, police said.
"You could see the foot that's inside the running shoe," she said. "The leg bones were coming out of the running shoe about 3 to 4 inches. There were no tissues or anything attached."
But she said the foot appeared to have been deliberately severed, as the bones "had been cut clean across."
The foot was the sixth discovered on shorelines in the area since August, according to local police and media reports. Another foot -- a left foot still in a shoe -- was found Monday on the shore of Westham Island, south of Vancouver. Police said it was taken to a coroner for DNA testing.
RE: Rumormonger: Is Google about to swallow up Digg?
Topic: Business
6:14 pm EDT, Jun 14, 2008
flynn23 wrote:
Google's cupcake princess, Marissa Mayer, and Kevin Rose, the playboy of the Webhead world, would make an awfully cute couple. Not romantically — the two are dating other people at the moment. But we hear Mayer is pushing hard for an acquisition of Rose's Digg, for a price below $200 million.
China denies hacking into US computers - Yahoo! News
Topic: Miscellaneous
5:12 pm EDT, Jun 12, 2008
China denied accusations by two U.S. lawmakers that it hacked into congressional computers, saying Thursday that as a developing country it wasn't capable of sophisticated cybercrime.