Trojan lurks, waiting to steal admin passwords

Wednesday, July 2nd, 2008

Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.They have managed to infect hundreds of thousands of computers, including more than 14,000 within one unnamed global hotel chain, by waiting for system administrators to log onto infected PCs and ...

Blizzard’s Two-Factor Authentication

Tuesday, July 1st, 2008

Blizzard's announcement of two-factor authentication for World of Warcraft is more significant than people realize. Passwords are obsolete. They are broken. We all recognize this, yet we aren't quite ready to give up on passwords because we haven't an easy alternative. World of Warcraft (WoW) is a good test case. It is ...

Teenager confesses to being Nugache botnet mastermind

Tuesday, July 1st, 2008

Experts at SophosLabs™, Sophos's global network of virus, spyware and spam analysis centers, have welcomed news that a teenager has confessed to controlling thousands of computers in an illegal botnet.19-year-old Jason Michael Milmont, of Cheyenne, Wyoming, has admitted to being the programmer of the Nugache malware which infected Windows computers, ...

Cracking Physical Identity Theft

Tuesday, July 1st, 2008

A researcher performing social engineering exploits on behalf of several U.S. banks and other firms in the past year has “stolen” thousands of identities with a 100 percent success rate.Joshua Perrymon, hacking director for PacketFocus Security Solutions and CEO of RedFlag Security, says organizations typically are focused on online identity ...

Hacker Launches Botnet Attack via P2P Software

Sunday, June 29th, 2008

A 19-year-old hacker is agreeing to plead guilty to masterminding a botnet to obtain thousands of victims' personal data in an anonymous scheme a federal cybercrime official described Friday as the nation's first such attack in which peer-to-peer software was the "infection point."The defendant, Jason Michael Milmont, launched the assault ...

BackTrack: A penetration testers toolset

Tuesday, June 17th, 2008

There are few job titles as misleading as that of the "Penetration Tester." Sure, saying professional computer hacker would be more direct, but have you ever noticed how hackers seem to have a dirty mind? Why else would they want to go phreaking through backdoors? Anyway, in order for hackers to ...

A Tour of Risky Web Sites

Wednesday, June 4th, 2008

Just over 4% of all Web sites are dangerous, according to a new report. But all bad sites aren’t created equal: Cyber bad guys are more likely to build their sites where it’s easy to do so. The report out today from McAfee, a tech-security company that’s trying to position itself ...

How to Harden Your Mac

Wednesday, June 4th, 2008

If you're a quasi-sophisticated Mac user and have been looking for advice on how to better safeguard your machine from hackers or local prying eyes, look no further: Apple has released a massive, 240-page guide that describes various methods for securing the operating system. According to SecurityFocus.com, the manual includes an ...

Shmoocon 2008 videos are now online

Sunday, June 1st, 2008

The videos from ShmooCon 2008 have hit the shelves. Go download them at: http://www.shmoocon.org/2008/videos/ EDIT: As of the time of this post, some of the videos are incorrectly named. Here is the 1-> 1: Correctly Named: 21st Century Shellcode for Solaris Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to SPIKE land Backtrack ...

PstPassword Recovers Lost Outlook Passwords

Friday, May 30th, 2008

Windows only: When you dig up that old Outlook PST (Personal Folders) file from years ago you cleverly secured with a hard-to-guess password—and now you can't guess it—you want PstPassword. Turns out that Outlook passwords aren't that difficult to figure out, because this handy utility detects the PST's on your ...