Tiger Team a review

Tiger Team hopes people turn there security around

Ok I take it all back, I was wrong. Tiger team is great. I thought it would be all style and no substance or really boring. But actually its very short (less that 20mins a episode) cut together into a reasonable paced documentatry. Its split into 5 pieces including part 4 the heist (yes 2 members of the camera crew do follow them into the heist) and part 5 the debrief. Its actually all good stuff and you get a good balance of social enginnering and computer exploits. For example they use a USB trojan and some social engineering on a receptionist to gain access to the internal network. Theres some technical material details but not enough to bore most people and maybe not enough to really be used for copycats. For example they don't say which software there using or how they pick locks. There's alot more analysis on the show in the Schneier blog post about the series. I wonder what some of these people would say about the real hustle?

The first episode was good but the second one really good because you could really see that it was a real challenge and they almost got caught too, which adds to the suspense. I really don't hope they don't cancel this series before it plays out. More photos here and because its not available in the UK, links to the torrents.

Technorati Tags: , , , , , , , ,

Comments [Comments]
Trackbacks [0]

Windows WMF Metafile Vulnerability fix from reverse engineer

Well is this is a good way to start 2006 Microsoft. A very serious exploit was found in Windows during last week, and this time its a 0day exploit which means there's no patch available from Microsoft yet. Actually Microsoft are advising people to unregister the shimgvw.dll which is not a fix in anyones wildest imagination.

But luckly some reverse engineer called Ilfak Guilfanov has reversed engineer the shimgvw.dll and written a patch which runs on all 32/64bit Windows (aka no 95, 98 or ME support). From what I've read, it sounds like the patch is pretty safe (llfak has actually open sourced the code I believe) so I would recommend you download this patch till Microsoft sort out an official patch. And honestly do it now as there are tons of worms written for this exploit and there coming from many different directions. IM, Email, Browser, etc, etc. Oh by the way theres a checker too.

Pass this information to as many people as you can…

Comments [Comments]
Trackbacks [0]