Chrome virus scanner coming

January 8, 2012 – 8:33 PM

Google has released a beta version of its Chrome 17 browser that scans for malicious downloads, which may help tackle scareware threats. The browser will issue a warning to discard a file when a user attempts to download a known bad file or if the file comes from a site known to host malware.  The new features build upon Google’s Safe Browsing system which warns if a site should not be trusted, but does not have a feature to detect malicious files from the web.  The blacklist used in the beta version is small but Google will be “ramping up coverage” in the coming months, engineer Dominic Hamon wrote in a blog post.  The new security feature comes after a Google sponsored study by security firm Accuvant found that Microsoft’s SmartScreen Filter and Google’s Safe Browsing detected under 15 percent of confirmed live malware URLs [pdf].

Source:
http://www.scmagazine.com.au/News/286274,chrome-virus-scanner-coming.aspx

Bug may enable remote code execution in Google Chrome

October 24, 2011 – 8:50 PM

Google Chrome contains a vulnerability that could allow an attacker to silently execute remote code on a victim’s machine outside of the browser’s built-in sandbox protections, according to researchers at Slovenia-based Acros Security.

According to Google, however, the issue is not technically a flaw, but rather a “strange behavior” that would require substantial user manipulation to exploit.

The issue, which Acros researchers disclosed to Google more than a month ago, could result in Chrome, under specific circumstances, loading an encryption configuration file from an insecure location, Mitja Kolsek, CEO of Acros Security, told SCMagazineUS.com on Monday. This could allow an attacker to execute remote code on a victim’s machine outside of the Chrome sandbox, intended to protect sensitive resources from being accessed by malicious code.

Source:
http://www.scmagazineus.com/bug-may-enable-remote-code-execution-in-chrome/article/215216/

NoScript for Mobile Devices

October 17, 2011 – 4:14 AM

This is the first feature-complete mobile version of NoScript. In other words, it provides all the major security features of its desktop counterpart which make sense on a mobile device.

http://hackademix.net/2011/10/15/noscript-for-mobile-is-complete/

Steve Jobs’ 2005 Stanford Commencement Address

October 8, 2011 – 4:12 PM

I still find myself going back and watching this every year or so.  Very motivating, especially for me right now.

Steve Jobs’ 2005 Stanford Commencement Address

Derbycon 2011 Videos

October 4, 2011 – 7:28 PM

I’m mainly archiving this for myself but, if you have an entire weekend to kill and want to learn from some of the best, here are all the videos from DerbyCon this past weekend.

http://www.irongeek.com/i.php?page=videos/derbycon1/mainlist