Friday, September 12, 2008

UNAM's Computer security conference

The UNAM's computer security conference will be held on September 25th-26th in Mexico city, the line-up includes (among others):

  • Eugene Schultz

  • Kimberly Zenz

  • Dr. Tom Holt

  • Peter Casidy

  • Lance Spitzner

  • Jess Vincent


Registration is now open for this 2-day event. The fee is $100 per person for both days.
Where: Palacio de Minería, downtown.
See you there two weeks from now.

Monday, August 25, 2008

New blog from my class

I've just added a link to a blog related to computer security topics from my class at UNAM. We'll be discussing fresh news and other info. Sorry, only spanish.

Monday, July 28, 2008

Heart defibrillators & security

A couple of weeks ago I received the printed version of "The Institute" newspaper from IEEE. Although not fresh news (I found some headlines dated March 13, 2008), there is an interesting article titled "hacking hearts" about the "hackability" of the human heart defibrillators.

Back in May the IEEE held a Symposium about privacy & security, and the topic of security of defibrillators was deeply discussed, "The researchers tricked the defibrillator into responding to their signals by recording a real device programmer talking electronically to a defibrillator, then replaying the signals wirelessly back to the defibrillator."

Were you concerned about your car's bluetooth connectivity?, what about this?

Friday, June 27, 2008

802.11n and vulnerabilities

With the upcoming release of IEEE's 802.11n standard, I've been looking for already known vulnerabilities with the draft-based (2.0) products that have been sold for a while.

There are some interesting URLs where you can dig, like WVE and Joshua Wright's website. The standard is planned to be released on November 2008, and so the "certified" products, so we expect to find exploits, vulnerabilities shortly after.

Friday, May 9, 2008

Mexican Senate's site hacked

Today the Mexican Senate's website has been hacked by a southamerican hacker group. It's been almost 10 years since that website was hacked by the X-ploit group. The people responsible for the Senate's website still have many lessons to learn.

Back to the roots

I'm back at the UNAM-CERT after spending 3 months at NextiraOne. And it's a good returning for me because I've been told I'll be teaching at the engineering school at UNAM, a course of selected topics on network security.

Tuesday, February 5, 2008

Security patch for the "2wire authentication vulnerability"

Today the UNAM-CERT has released an update to the security note published back in December 2007 that warned about an authentication vulnerability in the 2wire modems.

Last week the UNAM-CERT tested the new firmware that is scheduled to be released to the TELMEX users (prodigy Infinitum) later this month. The new firmware version is 5.29.135.5 and will be deployed in the next weeks. It is important to say that the update is automatic.

The complete information is here: http://www.cert.org.mx/nota/?vulne=5534