This looks ominous...
New attack bypasses virtually all AV protection • The Register
We feel passionate about most things related to computer security: Links, news, articles, research papers, etc...
Showing posts with label insecurity. Show all posts
Showing posts with label insecurity. Show all posts
Monday, 17 May 2010
Tuesday, 20 April 2010
Marc Maiffret--the quick rise of a teen hacker
Insightful interview with March Maiffret who wrote Retina:
Marc Maiffret--the quick rise of a teen hacker (Q&A) InSecurity Complex - CNET News
Marc Maiffret--the quick rise of a teen hacker (Q&A) InSecurity Complex - CNET News
Monday, 15 March 2010
Spy Eye trojan kills Zeus
Not for the first time, one trojan tries to kill another:
http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival/
http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival/
Tuesday, 9 February 2010
Wednesday, 16 September 2009
Attack of the open source zombies
A cluster of web servers serving both legitimate content and malware:
http://www.theregister.co.uk/2009/09/12/linux_zombies_push_malware/
http://www.theregister.co.uk/2009/09/12/linux_zombies_push_malware/
Wednesday, 2 September 2009
RSA whitepaper on security implications of virtualised environments
Although fairly VMWare/EMC centric in the solutions section, this paper raises some important considerations with regards to security in a virtualised environment related to:
Registration required:
https://rsa-email.rsa.com/servlet/campaignrespondent?_ID_=rsa.4696&WPID=10393
- Platform hardening,
- Configuration and change management,
- Administrative access control,
- Network security and segmentation,
- Audit logging.
Registration required:
https://rsa-email.rsa.com/servlet/campaignrespondent?_ID_=rsa.4696&WPID=10393
Tuesday, 14 July 2009
Your mobile number available to anyone?
This looks like a genuine worry:
http://news.bbc.co.uk/1/hi/programmes/working_lunch/8091621.stm
This potentially opens the door to more SMS spam to find its way to your inbox.
This should be an opt in service rather than opt out.
You can either send a text to 118800 or do it on their website, which must be hammered as it is down:
http://www.118800.co.uk/
The Guardian seems to confirm this:
http://www.guardian.co.uk/money/2009/jul/13/mobile-phone-directory-suspended
http://news.bbc.co.uk/1/hi/programmes/working_lunch/8091621.stm
This potentially opens the door to more SMS spam to find its way to your inbox.
This should be an opt in service rather than opt out.
You can either send a text to 118800 or do it on their website, which must be hammered as it is down:
http://www.118800.co.uk/
The Guardian seems to confirm this:
http://www.guardian.co.uk/money/2009/jul/13/mobile-phone-directory-suspended
Friday, 10 July 2009
Kon Boot illustrates why physical security still matters most
http://www.piotrbania.com/all/kon-boot/
This little utility allows modification of the Windows and LINUX kernel whilst booting to allow log on without knowing the password.
This little utility allows modification of the Windows and LINUX kernel whilst booting to allow log on without knowing the password.
Tuesday, 26 May 2009
We truly never learn!
Laptop left in boot of car overnight in Edinburgh contained information about thousands of soldiers...
http://news.scotsman.com/scotland/Army39s-stolen--laptop-sparks.5283785.jp
http://news.scotsman.com/scotland/Army39s-stolen--laptop-sparks.5283785.jp
I use a Mac so I'm ok
Java vulnerability on Mac is still not patched 6 months on:
http://www.theregister.co.uk/2009/05/19/unpatched_apple_vulnerability/
It sounds like it is being actively exploited. The mitigation is to disable the browser's Java applets as well as the "Open safe files after downloading" setting in Safari.
http://www.theregister.co.uk/2009/05/19/unpatched_apple_vulnerability/
It sounds like it is being actively exploited. The mitigation is to disable the browser's Java applets as well as the "Open safe files after downloading" setting in Safari.
What took them so long to get infected?
The U.S. Marshals Service, a division of the Department of Justice, recently got crippled by Neeris. The virus was first discovered on 12th September 2007. The service was running anti malware, but that had not been updated for three years, and Windows patches had not been applied either.
http://www.networkworld.com/news/2009/052109-marshall-malware.html?hpg1=bn
http://www.networkworld.com/news/2009/052109-marshall-malware.html?hpg1=bn
Wednesday, 24 September 2008
CSI Stick me baby
This is sooooooo cool, I want one, I want one, gimme, gimme.
http://news.cnet.com/8301-1009_3-10028589-83.html
Now off to practice my slight of hand and magic fingers so I can connect it to phones without people seeing! :)
dD
http://news.cnet.com/8301-1009_3-10028589-83.html
Now off to practice my slight of hand and magic fingers so I can connect it to phones without people seeing! :)
dD
"Lloyds is Pants" no good enough PWD
This made me laugh, apparently abusing a service provider via your password is not appropriate: http://news.bbc.co.uk/1/hi/england/hereford/worcs/7585098.stm
However, what is more disconcerting is the apparent ability in some cases, for business users only, Employees of Lloyds can read your complete password. This seems somewhat ridiculous as businesses surely would have more money flowing through their accounts than an individual, so would become a richer target! IT MAKES NO SENSE (as Tim Westwood would say).
dD
P.S. Thanks to SchneierBad security by design/stupidity
Heads up to the great god schneier for pointing us to this one. Looks like the Tornado Plus encrypted USB drive is the perverbial pile of poo. Check out this rather scathing write up on Tech republic by Tom Olzak.
http://blogs.techrepublic.com.com/security/?p=573&tag=nl.e019
dD
http://blogs.techrepublic.com.com/security/?p=573&tag=nl.e019
dD
Tuesday, 26 August 2008
Red Hat with a Red Face
Unfortunately writing and maintaining open source does not protect one from malicious minds:
https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html
It sounds like they are doing the "right" thing by revoking old package signing keys and generating new ones.
https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html
It sounds like they are doing the "right" thing by revoking old package signing keys and generating new ones.
Thursday, 24 April 2008
2008 Information Security Breaches Survey
This survey is published every other year, and the results were published at the Infosecurity exhibition in London this week.
The executive summary and the full report can be found here:
http://www.pwc.co.uk/eng/publications/berr_information_security_breaches_survey_2008.html
The executive summary and the full report can be found here:
http://www.pwc.co.uk/eng/publications/berr_information_security_breaches_survey_2008.html
Tuesday, 22 April 2008
Privilege escalation in Windows
MS released an advisory last week which makes for interesting reading:
http://www.microsoft.com/technet/security/advisory/951306.mspx
Vulnerable version start with XP all the way to Windows Server 2008.
http://www.microsoft.com/technet/security/advisory/951306.mspx
Vulnerable version start with XP all the way to Windows Server 2008.
Friday, 14 March 2008
SNMP Walking
Really interesting experiment from the GNUCitizen folks: 2.5 million random IP addresses were scanned via SNMP, 5320 IP addresses responded including: Windows 2000 Servers returning a list of usernames, BT Voyager router leaking ISP credentials and password, etc...
http://www.gnucitizen.org/blog/exploring-the-unknown-scanning-the-internet-via-snmp/
http://www.gnucitizen.org/blog/exploring-the-unknown-scanning-the-internet-via-snmp/
Subscribe to:
Posts (Atom)