637 million Web surfers using old browsers open to hackers

Wednesday, July 2nd, 2008

Updated your Web browser lately? Ever? If not, you and 637 million other Net surfers with outdated, insecure browsers are inviting criminal hackers into your computer, researchers warn.Using Internet Explorer? You're likely to be one of the biggest offenders.The researchers wanted to know why so many recent attacks have been ...

Cross Environment Hopping

Tuesday, July 1st, 2008

Our research team has identified a web-based attack technique that exploits the growing number of applications that require a web server being run on a local machine. Cross-Environment Hopping (CEH) is a result of this trend combined with the current limitations in browsers’ same-origin policy access restrictions.The CEH technique enables ...

Exploit code released for unpatched IE 7 vulnerability

Tuesday, July 1st, 2008

Another day, another gaping hole affecting fully patched versions of Microsoft’s Internet Explorer browser.According to a warning from US-CERT, proof-of-concept exploit code has been published for a new zero-day bug that can be used for a variety of malicious attacks against Windows users running IE 6, IE 7, and IE ...

Many weak web server certificates threaten online shopping

Monday, June 30th, 2008

"https connections exist to help ensure that when somebody is engaged in a financial transaction over the internet they are actually connected to the correct site - such as a bank, online vendor, and so forth. However, due to an error in the OpenSSL library used by the Debian Linux ...

Taming Internet Explorer Browser Plug-Ins

Sunday, June 29th, 2008

Security Fix has often lamented the lack of decent point-and-click software tools to help Microsoft Internet Explorer Web browser users kill insecure "ActiveX controls," plug-ins for IE that have traditionally been among the biggest avenues of attack from spyware and adware. That's why I'm pleased to call attention to a ...