Bot breaks Hotmail’s CAPTCHA in 6 seconds

Monday, April 14th, 2008

A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday. Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test ...

Vulnerability in Google spreadsheets allows cookie stealing

Monday, April 14th, 2008

Security researcher Billy Rios has discovered a vulnerability in Google Spreadsheets which attackers can exploit using links to crafted tables to steal a user's cookie. According to Rios, the victim has to follow such a link in Internet Explorer. The stolen cookie can be used to access all Google services ...

Password theft via vulnerability in Google code

Monday, April 7th, 2008

Billy Rios has discovered a vulnerability in the Google Code service which could be exploited to steal passwords from developers who have registered on the site. The Google Security Team has since fixed the vulnerability. Rios succeeded in gaining cross-domain access by uploading a crafted Java applet to a project on ...

Google Maps diminishing value of homes, causing “mental suffering”?

Saturday, April 5th, 2008

A couple is accusing Google of diminishing the value of their property and causing them "mental" suffering" for including their recluse home in the Google Maps Street View project. The road leading up to their house is apparently labeled "private", something the Street View operator must've missed. We checked the ...

Analysis of a Win32.Delf Variant

Friday, April 4th, 2008

We have been noticing quite a few malware samples having references to or communicating with Google's SMTP servers. This post dissects one of these samples and in the process attempts to illustrate to the reader some reversing techniques and information gathering techniques, while explaining the behavior and impact of this ...

Phishers Use Google to Find Exposed Servers

Sunday, March 30th, 2008

Three-quarters of phishing sites are built on hacked servers that have been tracked down using pre-programmed Google search terms, according to research from brand-protection firm MarkMonitor. Among other activities, MarkMonitor tracks phishing attacks that target brand names. Researchers compiled a list of 750 Google search terms that are used to track down ...

Massive IFRAME SEO Poisoning Attack Continuing

Friday, March 28th, 2008

Last week's massive IFRAME injection attack is slowly turning into a what looks like a large scale web application vulnerabilities audit of high profile sites. Following the timely news coverage, Symantec's rating for the attack as medium risk, StopBadware commenting on XP Antivirus 2008, and US-CERT issuing a warning about ...

Goolag - GUI Tool for Google Hacking

Thursday, March 13th, 2008

cDc (Cult of the Dead Cow) recently released a GUI driven tool for Google Hacking called Goolag. Google Dorks have been around for several years and have been researched most assiduously by Johnny I Hack Stuff. If one searches the Web, one will find multiple collections of dorks, and also some applications ...

EU Approves Google’s DoubleClick Buy

Tuesday, March 11th, 2008

Google announced their intention to acquire ad service company DoubleClick back in April last year. Today, Reuters reports: Google won unconditional approval from the European Commission on Tuesday to buy rival Web advertiser DoubleClick for $3.1 billion, despite objections from rivals and privacy advocates. Google has already won approval from United States ...

Things You Didn’t Know You Could Do With Google

Tuesday, March 11th, 2008

Every time I turn around, Google's come up with something new, cool, or innovative. It's no wonder it has Microsoft on the run. Nifty Google Features Calculate This: You can use Google Calculator to crunch numbers and figure out conversions. Try entering 12*12 and see what happens; you can also run more ...