OpenDNS Can Help Protect Against DNS Rebinding Attacks

July 31, 2010 – 12:06 PM

This feature has been around for a while but I wanted to make sure everybody knows that if you are an OpenDNS customer you have a nice option in your Control Panel to help protect against DNS Rebinding attacks.  This feature is turned off by default but you can enable it in the Settings > Security area for your particular network:

You can read more about DNS Rebinding attacks here:
https://secure.wikimedia.org/wikipedia/en/wiki/DNS_rebinding

Most SSL Sites Poorly Configured

July 31, 2010 – 8:16 AM

The good news about SSL-based websites: Most are running strong encryption. The bad news: More than 60 percent aren’t properly configured.

Researcher Ivan Ristic, who is director of engineering, Web application firewall, and SSL at Qualys, revealed findings here yesterday from a study he conducted of some 120 million registered domain names. Ristic found that 20 million of them support SSL, but only 720,000 of these have potentially valid SSL certificates. “That’s a very small percentage, but it doesn’t really mean anything apart from that a fraction of sites use SSL, which we’ve known,” Ristic say.

Of the more telling findings was that of all the SSL sites, half use SSLv2, an older version of SSL, which is known to be insecure. Only 38 percent of all SSL sites are actually configured well, Ristic says, and 32 percent contain a previously exposed renegotiation vulnerability in the protocol.

Meanwhile, researchers Robert “RSnake” Hansen and Josh Sokol here yesterday detailed some 24 exploitation techniques possible against HTTPS/SSL for browsers that leverage man-in-the-middle (MITM) attacks. Among them: cookie poisoning and injecting malicious content into browser tabs. The researchers warned that HTTPS can’t guarantee confidentiality and integrity in the browser.

Source:
http://www.darkreading.com/securityservices/security/vulnerabilities/showArticle.jhtml?articleID=226400077

171 Million Facebook Profiles Scraped

July 27, 2010 – 6:22 PM

Turns out that Facebook has a directory where you can get a list of all searchable FB users:

https://www.facebook.com/directory

These are now scraped and the torrent file is available for download for anybody who wants it.

More info:
http://www.skullsecurity.org/blog/?p=887

Update Google Chrome

July 26, 2010 – 9:13 PM

Google Chrome 5.0.375.125 has been released to the Stable channel on Linux, Mac, Windows, and Chrome Frame.

Download:
http://www.google.com/chrome?hl=en

Block the Windows Shortcut Exploit

July 26, 2010 – 7:58 PM

The Windows Shortcut Exploit is a zero-day vulnerability in all versions of Windows that allows a Windows shortcut link to run a malicious DLL file. Sophos now has a free, easy-to-use tool blocks this exploit from running on your computer.

Please note: Existing Sophos Endpoint customers are already protected from the Windows Shortcut Exploit and do not need to install this tool.

Tool:
http://downloads.sophos.com/custom-tools/Sophos%20Windows%20Shortcut%20Exploit%20Protection%20Tool.msi

Source:
http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html