Skip to main content

Posts

Showing posts from July, 2012

Blogger Traffic Source Spam / StumbleUpon Hacked?

{ Update : there is a new bit of Linux malware making the rounds that likes to play games with iframes. Comprehensive descriptions of the exploit are listed below - of particular interest is the write up on Crowdstrike. I don't have enough data to know for sure if the two events are related as nothing I administrate has been compromised, but the iframe mechanism is fairly unique in both cases. https://www.securelist.com/en/blog/208193935/New_64_bit_Linux_Rootkit_Doing_iFrame_Injections https://threatpost.com/en_us/blogs/new-linux-rootkit-emerges-112012 http://blog.crowdstrike.com/2012/11/http-iframe-injecting-linux-rootkit.html http://linux.slashdot.org/story/12/11/20/1733237/new-linux-rootkit-emerges Here is my comment on the Slashdot Article: http://linux.slashdot.org/comments.pl?sid=3263519&cid=42074663 } I usually take a quick look at this site's traffic and referral sources following a post. One of the great things about having a circulation close to

PCI Compliance Scans and Scams

HIPAA, SOX, SAS-70 - those whose business relies on hosting a website are no stranger to the regulatory schemes of trade organizations and their acronyms. The PCI Data Security Standard is perhaps the most well known and widely adopted. PCI DSS is a set of very general outlines of security best practices for those who process and/or store credit cards using computers. Compliance is certified by a third party corporation (a Qualified Security Assessor or QSA), and demand is created by offering lower credit card transaction fees to websites who are certified as compliant. On the whole, the initiative has had some big successes. Credit card companies win by reducing incidents of fraud as more sites adopt standard security features, merchants win through reduced transaction costs and by being able to advertise a third party certification of secure site design and companies responsible for certification get to exist and create new jobs in the process. The standards have gone a long way to

How My Laptop Survived a Tornado (Or, Buy a Toshiba Satellite C655)

Tropical Storm Debby recently made my acquaintance at my humble home here in South Florida. The storm itself was a non-starter, but apparently the outer strands of it spawned a series of tornadoes across Florida last Sunday.  While I am pretty handy with a computer, when it comes to un-nerd-related topics I am oblivious, and on Sunday I was unaware of Debby or the tornado warning that had been issued. It was sunny outside that day - if I had heard something I would have written it off as a false alarm anyway.  My home is on a lake and surrounded by trees. My favorite part of the house is the expansive back porch. The porch is screened and runs the entire length of the house - we've installed a hammock whose awesomeness cannot be translated into English as well as a large hand crafted wooden table. I tend to do my drinking in the hammock while whittling away the hours with a great view of the lake. The table is for when I actually need to get some work done or eat something. Bet