Firefox Extension Blocks Dangerous Web Attack

Wednesday, October 8th, 2008

A popular free security tool for the Firefox browser has been upgraded to block one of the most dangerous and troubling security problems facing the Web today. NoScript is a small application that integrates into Firefox. It blocks scripts in programming languages such as JavaScript and Java from executing on untrusted ...

Net game turns PC into undercover surveillance zombie

Tuesday, October 7th, 2008

Underscoring the severity of a new class of vulnerability known as clickjacking, a blogger has created a proof-of-concept game that uses a PC's video cam and microphone to secretly spy on the player. The demo, which is available here, appears to be a simple game that tests how quickly a user ...

DNS poisoners hijack typo domains

Friday, August 22nd, 2008

Websense, the security services provider, has reported a successful case of cache poisoning on name servers of one of the largest Chinese ISPs. Netcom customers are said to have been steered by criminals to manipulated pages on which exploits for RealPlayer, MS Snapshot Viewer, Adobe Flash Player and Microsoft Data ...

Massive faux-CNN spam blitz uses legit sites to deliver fake Flash

Wednesday, August 6th, 2008

More than a thousand hacked Web sites are serving up fake Flash Player software to users duped into clicking on links in mail that's part of a massive spam attack masquerading as CNN.com news notifications, security researchers said today.The bogus messages, which claim to be from the CNN.com news Web ...

Adobe: Beware of fake Flash downloads

Tuesday, August 5th, 2008

Amidst confirmed reports that malicious hackers are starting to use fake Flash Player downloads as social engineering lures for malware, Adobe has issued a call-to-arms for users to validate installers before downloading software updates.The company’s notice comes on the heels of malware attacks on Facebook, MySpace and Twitter that attempt ...

Social engineering on Twitter

Monday, August 4th, 2008

This week it’s Twitter’s turn to host an attack - one that is targeting both Twitter users and the Internet community at large. In this case it's a malicious Twitter profile twitter.com/[skip]/ with a name that is Portuguese for ‘pretty rabbit’ which has a photo advertising a video with girls ...

SSDs save battery power, right? Wrong!

Tuesday, July 1st, 2008

If you just shelled out some pretty pennies for the a high-speed, low-power SSD, Tom's Hardware may have stumbled onto some findings that won't sit well. According to a rigorous benchmarking session, they discovered that not only do the drives not save you battery power... they eat more of it. ...

Searchable SWFs

Tuesday, July 1st, 2008

I got forwarded this link today from businesswire about how Google and Yahoo are now going to be armed with the information necessary to look at and extract information out of SWF files. Ho-boy, here we go. The link was sent to me with the “bad juju” caveat, and I’m ...

All clear for Flash Player: current version not vulnerable

Monday, June 2nd, 2008

The reported security hole in Flash Player can now be given the all clear. The general consensus is that users of the current version 9.0.124.0 are safe. For the first time ever Secunia, one of the most reliable sources of information about security issues, has even revoked its advisory about ...

XSS Methods Also Seen Being Used in Mass Compromises

Sunday, June 1st, 2008

XSS (Cross-Site Scripting) Very Much Alive and Kicking We were about to investigate further on malicious activities related to banner82(dot)com/b.js but the URL was already inaccessible around Tuesday. Soon enough the malicious script in www(dot)adw95(dot)com caught our interest. A rough survey of the sites compromised by this script reveal that the ...