Researcher to Demonstrate Attack Code for Intel Chips

Monday, July 14th, 2008

Security researcher and author Kris Kaspersky plans to demonstrate how an attacker can target flaws in Intel's microprocessors to remotely attack a computer using JavaScript or TCP/IP packets, regardless of what operating system the computer is running. Kaspersky will demonstrate how such an attack can be made in a presentation at ...

ISPs Join to Block Child Porn

Sunday, July 13th, 2008

AT&T Inc. and AOL LLC have joined three other major Internet service providers in eliminating access to child pornography newsgroups, New York Attorney General Andrew Cuomo said Friday. In June, Verizon Communications Inc., Time-Warner Cable and Sprint Nextel Corp. signed an agreement with Cuomo to shut down access to two major ...

Crawling AJAX

Saturday, July 5th, 2008

Traditionally, a web spider system is tasked with connecting to a server, pulling down the HTML document, scanning the document for anchor links to other HTTP URLs and repeating the same process on all of the discovered URLs. Each URL represents a different state of the traditional web site. In ...

Kaspersky adds anti-keylogger keyboard

Tuesday, July 1st, 2008

The new version of Kaspersky's security suite, Internet Security 2009, features a novel but simple defense against keylogging malware -- a virtual keyboard. Full details have yet to be confirmed, but it is understood that the program will let users bring up the keyboard from which to enter login details for ...

Cross Environment Hopping

Tuesday, July 1st, 2008

Our research team has identified a web-based attack technique that exploits the growing number of applications that require a web server being run on a local machine. Cross-Environment Hopping (CEH) is a result of this trend combined with the current limitations in browsers’ same-origin policy access restrictions. The CEH technique enables ...

Storm Is Back–With Porn Scam

Sunday, June 22nd, 2008

Security researchers Friday warned of a new, massive spam campaign that tries to convince users to install the long-running Storm bot Trojan on their PCs. The new spam blitz is difficult to characterize, said researchers from MX Logic Inc. and F-Secure, because of the nearly 40 different subject heads used by ...

Corporate Security Worldwide Fails Basic Tests

Sunday, June 22nd, 2008

Everyone knows that there's no such thing as 100 percent security, but it's unlikely that most businesses realize how insecure they really are. New research on endpoint security shows just how vulnerable corporate networks are. Eighty-one percent of corporate endpoints probed by IT security and control product vendor Sophos failed basic ...

Cain & Abel v4.9.15 released

Saturday, June 21st, 2008

Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords ...

The Extended HTML Form attack revisited

Wednesday, June 18th, 2008

"HTML forms (i.e. <form>) are one of the features in HTTP that allows users to send data to HTTP servers. An often overlooked feature is that due to the nature of HTTP, the web browser has no way of identifying between an HTTP server and one that is not an ...

Site Security Policy

Sunday, June 8th, 2008

OK gang, this is one of those rare moments where feedback from community will directly influence a security feature that’ll make a real difference. First some background... About 6 months ago Brandon Sterne left a cushy infosec position at eBay for Mozilla to solve an extremely important Web security problem he ...