Hex Workshop 6 is released :)

Hex Workshop 6 has been released, well.. *cough* I am a bit behind in reverse engineering news unfrotunately, blame life!

it has a nice GUI, new set of features like color mapping (is that a real feature? :P), haven’t yet tested it completely like I’ve done with the older versions of it, I think it has some complexity, not sure though, I will try to post some feedback later on it once I give it a real try 🙂

Microsoft Press Books of the Month

SSL broken!

Hackers create rogue CA certificate using MD5 collisions!

Using computing power from a cluster of 200 PS3 game consoles and about $700 in test digital certificates, a group of hackers in the U.S. and Europe have found a way to target a known weakness in the MD5 algorithm to create a rogue Certification Authority (CA), a breakthrough that allows the forging of certificates that are fully trusted by all modern Web browsers.

The research, which will be presented today by Alex Sotirov (top left) and Jacob Appelbaum (bottom left) at the 25C3 conference in Germany, effectively defeats the way modern Web browsers trust secure Web sites and provides a way for attackers to conduct phishing attacks that are virtually undetectable.

The research is significant because there are at least six CAs currently using the weak MD5 cryptographic algorithm in digital signatures and certificates.  The most commonly used Web browsers — including Microsoft’s Internet Explorer and Mozilla’s Firefox — whitelist these CAs, meaning that a fake Certificate Authority can display any site as secure (with the SSL padlock).

We basically broke SSL,” Sotirov said in an interview ahead of his 25C3 presentation.

بأبي أنت وأمي يا رسول الله

Writing Secure Code for Windows Vista

Book of the month by Microsoft Press free to download.

and happy new year everyone 🙂

Password: (included)