Archive for the ‘Coding’ Category

CSS exploit allows detection of social site use

Thursday, May 29th, 2008

Web developer Aza Raskin knows we visit Digg, Del.icio.us, Reddit and Facebook without even having to ask. No, he isn't employing privacy violating hackery, but he is exploiting a "cute" information leak in CSS that traditionally displays visited links differently than those that have yet to be visited. By loading in ...

New Adobe Flaw Being Used in Attacks

Tuesday, May 27th, 2008

An unpatched bug in Adobe Systems' Flash Player software is being exploited by online criminals, Symantec reported Monday. Few details on the bug are available, but the flaw lies in the latest version of the Adobe Flash Player browser plugin, which is widely used by Internet surfers to view animated Web ...

Newest Firefox Beta has Critical Flaws, Mozilla Admits

Saturday, May 24th, 2008

Mozilla has identified 10 high-priority bugs in Firefox 3.0, three of them pegged "critical," but won't decide until next week whether to release the browser anyway or restart the final stretch by issuing a second release candidate (RC2). "We are making a go/no go decision early next week, as we are ...

Secunia PSI - Personal Software Inspector

Saturday, May 24th, 2008

The Secunia PSI is the FREE security tool that is designed with the sole purpose of helping you secure your computer from software vulnerabilities. Software vulnerabilities affect all applications installed on your computer, from the Operating System down to your email client, office application, instant messaging, and so on. A software ...

Facebook security snafu could compromise accounts

Friday, May 23rd, 2008

A researcher has spotted a security problem in Facebook that could lead to hackers taking control of user accounts. The flaw allows a hacker to execute scripts on Facebook that could potentially be used to create a fake log-in page and capture people's passwords, according to the XSSED security blog. The ...

Firefox Heap Corruption

Wednesday, May 21st, 2008

I forgot to tell you all about this actually. I found this about 8 months back and never discussed it for various reasons. Since I saw that Mozilla has fixed a lot of memory leaks inside Firefox 2/3, I guess it's safe to say I can talk about this now. ...

HTTP Proxies Bypass Firewalls

Tuesday, May 20th, 2008

This may seem painfully obvious to some people, but I looked around and couldn’t find a reference to it, so I apologize ahead of time for anyone who already knew this. When we normally think of how attackers use proxies they are almost always just trying to hide their IP ...

Permanent Denial-of-Service Attack Sabotages Hardware

Tuesday, May 20th, 2008

You don’t have to take an ax to a piece of hardware to perform a so-called permanent denial-of-service (PDOS) attack. A researcher this week will demonstrate a PDOS attack that can take place remotely. A PDOS attack damages a system so badly that it requires replacement or reinstallation of hardware. Unlike ...

Firefox developers tinker with new security protections

Tuesday, May 20th, 2008

Developers of the Firefox browser are designing new technologies aimed at protecting users from some of the nastiest and most prevalent forms of website attacks. One protection is designed to minimize end users' risk to cross-site scripting (XSS) attacks and cross-site request forgeries (CSRFs), both of which subvert basic internet security ...

Tomorrow’s Malware

Tuesday, May 20th, 2008

My favorite tech quote is from Giorgio Maone. It goes like this: If today’s malware mostly runs on Windows because it’s the commonest executable platform, tomorrow’s will likely run on the Web, for the very same reason. Because, like it or not, Web is already a huge executable platform, and ...