If you like it here, please consider subscribing to the RSS feed or spreading the news among your friends who also care about security.

July 9, 2008

IT Risk management in Wrocław once again (July 23.)

Since the meeting didn’t work out the last time due to some unexpected circumstances, please let me invite you to the event again. The agenda stays the same.

When: July 23, 6PM

Where: Credit Suisse, Kameleon building at Szewska st., 1st. floor

See you at the meeting!

June 28, 2008

IT Risk management in Wrocław on July 3.

I haven't posted in ages! I've even managed to forget the MT backend script name (not to mention I've lost my bookmarks somewhere down the road). But I'm back! Unfortunately I'm still busy as... well... as someone very busy, so I'll keep it short this time.

To the point: if you're from Wrocław area or if you happen to be around on July 3, be sure to come to the ISSA Polska meeting in Wrocław. We plan the meeting to be real fun this time. We'll be having a guest from Credit Suisse IT Risk dept. giving a talk. We also plan to discuss latest incidents in Poland.

When: July 3, 6PM

Where: Credit Suisse, Kameleon building at Szewska st., 1st. floor

See you there!

May 6, 2008

A piece of phishing email

Not that long ago I got this:

VISA phishing email

When was the last time you got a phishing email? Not that long ago, I bet. Me too. There is nothing unusual in it, nowadays we get so much of it that we simply get used to it and usually just silently delete or ignore it (if spam filters don’t do it for us).

So, why am I talking about this? Well, because of a funny coincidence. Or maybe it wasn’t that much of a coincidence… Here is the story.

Continue reading "A piece of phishing email" »

Fifth ISSA meeting in Wroclaw (May 19, 2008)

ISSA Polska

We're gonna do it for the fifth time already! Whooohoo! :)

This time the main theme will be Intrusion Detection Systems and Web Application Firewalls. Also a discussion panel is planned so that we all could shout at each other and throw blunt objects in each other’s general directions.
Here is the agenda:

1. A warm welcome (myself)
2. Intrusion Detection Systems (Wojtek Wirkijowski)
3. Web Application Firewalls (Edward Weinert)
4. Discussion Panel (Andrzej Piotr Kleśnicki)

And as always, there is a prize to be won.

See you at the meeting!

April 30, 2008

A funny thing with Thunderbird

I’m using Thunderbird as my email client on a daily basis. Not that long ago I’ve been trying to send a PDF document, that I previously got from the Web, as an email attachment. To my surprise the normal drag’n’drop and send routine didn’t do it. A short glance at the filename made it obvious — the percent-encoded forward slashes (%2F) in the filename got in the way.

As probably most of you guys, I’m not spending my day fuzzing stuff, but, probably as most of you again, I’m bumping over a software glitch from time to time. Sometimes, when I’m in the mood, I’m poking the hole to see what happens.

And I was in the mood that day.

Continue reading "A funny thing with Thunderbird" »

April 14, 2008

After ISSA Wroclaw meeting #4

ISSA Wrocław

It's been hands-on and it's been fun! :) Huge thanks goes to Edi Weinert and Tadeusz Kowalczyk who put all this together and made the whole thing possible. And of course thanks to you all! I hope you enjoyed the workshop and we'd really love to hear your comments on what we could do better next time.

Hope to see you next time! And in the meantime, be sure to click at the photo for more geeky shots.

Thank you all once again!

March 13, 2008

After the 3rd ISSA meeting in Wroclaw

ISSA Polska

Thank you! Thanks to all of you who made it to the meeting despite the fact that we have changed the location twice. And my apologies to all of you, who didn’t. We will do our best to make sure it doesn’t happen anymore.

Despite all the trouble, the meeting was fun. We totally run out of schedule due to discussions that broke out during the first talk. Oh, and the cookies were awesome! Not to mention the coffee.

We have one piece of slides this time, so, for all of you who would like to go through the presentation again and for others that didn’t make it to the meeting, here it is.

Thanks again and see you next month!

March 3, 2008

Third ISSA meeting in Wroclaw (Mar 11, 2008)

ISSA Polska

Let me invite you to another ISSA meeting in Wroclaw. It’s the third meeting already and this time we’ll be discussing Computer Forensics and Incident Response. We’ll be having a discussion panel as the last time and we’ll let you guys win some prizes in a competition.

All that and even more on Mar 11, 2008 at 6pm.

Where? At BZ WBK Wroclaw HQ, Rynek 9/11 (second door if you look from the pl. Solny direction). At Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).

An important note: you need to register for the meeting before Feb 4, 2008, 9pm at the latest. In order to register, please use the following link.

UPDATE: This time we meet at Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).

February 25, 2008

Automatische Antwort

What do you think happens when some spamming bots pick up your email address and start using it as a source address when throwing discounted Viagra and almost-like-the-real-thing watch replicas crap at people in unbelievable amounts?

Tons, and I mean TONS, of "undeliverable message" bounces together with quite a lot of my favourites – out of office notes. When you think about it, quite a lot of information is being thrown at you in such messages. Here are some sanitised examples (all in German, as my email address sells on a German market, apparently).

Continue reading "Automatische Antwort" »

February 19, 2008

Xploit #1

For all of you guys around here in Poland, another opportunity to deepen your acquaintance with information security just appeared. The first issue of Xploit have just hit the shelves.

Xploit 1/2008

What’s in it?

  • A remote DoS on Vista,
  • A tale of a deadly Android,
  • A short story of hacking PSP,
  • Everything you ever wanted to know about hosting, but were afraid to ask,
  • Challenges of risk analysis,
  • Securing SQL Server 2005,
  • Polish law and hacking,
  • TPM in GNU/Linux,
  • and much, much more.
All in Polish with a conventional live CD included.

I had a pleasure to share some thoughts on risk analysis in this issue, so be it only for that I really encourage you to visit your newsagent and give this fine new magazine a try.

Continue reading "Xploit #1" »

© 2006-2007 Michał Sobiegraj. All rights reserved. The views expressed here are my own, and not necessarily endorsed by any former or current employer.