Archive for the ‘Privacy’ Category

Microsoft hints at “private browsing” feature in IE

Wednesday, August 20th, 2008

One of the most interesting feature that didn’t quite make it into the final release of Firefox 3 is “Private Browsing”, a.k.a. porn mode. The only other browser with this feature built-in today is Safari (another reason to try it in case you haven’t), however, Microsoft may also be building ...

OpenVAS - Open Vulnerability Assessment System

Tuesday, August 19th, 2008

As you all probably known since version 3 Nessus turned to a proprietary model and started charging for the latest plugins locking most of us out. Now we finally have a new, properly organised forked development with the name of OpenVAS - at last a decent and free Vulnerability Scanner!OpenVAS ...

Clipboards hijacked in web attack

Tuesday, August 19th, 2008

Computer security firms are warning about an attack that hijacks the clipboard where copied text is stored.The attack puts a hard-to-delete weblink into the clipboard that, if followed, leads people to a website selling fake security software.The code that inserts the link has been found in flash-based adverts seen on ...

Fake MSNBC news alerts used in latest malicious spam campaign

Wednesday, August 13th, 2008

IT security and control firm Sophos is reminding computer users to exercise diligence when checking their email in the wake of a new widespread wave of dangerous spam messages that claim to be breaking news alerts from MSNBC. Samples intercepted at SophosLabs, Sophos's global network of virus, spyware and spam ...

New Gpcode (encryption) ransomware speading via botnet

Wednesday, August 13th, 2008

There are confirmed reports on a new version of the Gpcode ransomware being spread via a botnet.According to Vitaly Kamluk of Kaspersky Lab (my employer), the Trojan encrypts files on an infected machine (AES-256) and leaves a text file named crypted.txt with a ransom note demanding $10 to decrypt the ...

Keyczar - Google’s crypto for non-cryptographers

Tuesday, August 12th, 2008

Google has released Keyczar, billed as a "Toolkit for safe and simple cryptography", under an Apache 2.0 open source licence. Keyczar has been developed by members of the Google security team and aims to make cryptography more accessible to application developers.Keyczar's design goals were to manage the complexity of cryptography ...

Surf Jack - HTTPS will not save you

Monday, August 11th, 2008

Say hello to a new security tool called “Surf Jack” which demonstrates a security flaw found in many public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag. I’ve been working with two banks ...

New Tool to Automate Cookie Stealing from Gmail, Others

Sunday, August 10th, 2008

A security researcher at the Defcon hacker conference in Las Vegas on Saturday demonstrated a tool he built that allows attackers to break into your inbox even if you are accessing your Gmail over a persistent, encrypted session (using https:// versus http://). When you log in to Gmail, Google's servers will ...

An Illustrated Guide to the Kaminsky DNS Vulnerability

Sunday, August 10th, 2008

The big security news of Summer 2008 has been Dan Kaminsky's discovery of a serious vulnerability in DNS. This vulnerability could allow an attacker to redirect network clients to alternate servers of his own choosing, presumably for ill ends.This all led to a mad dash to patch DNS servers worldwide, ...

Malicious Hackers Use Facebook Wall for Malware Attack

Thursday, August 7th, 2008

Facebook users are being targeted by malicious hackers through postings on the popular Wall section of the social-networking site, security companySophos said Thursday.The Wall, a core feature of Facebook profile pages, is used by members to leave each other messages that in addition to text can also contain photos, videos, ...