Reading EXIF data with Javascript

Sunday, May 11th, 2008

Inspired by a comment on Ajaxian, I killed another afternoon or two making a small library capable of reading EXIF data from JPEG images, figuring I would at least learn a bit about EXIF and the JPEG (and TIFF) image formats. Before we start, a small disclaimer. I'm somewhat of a ...

QuickTime 0day for Vista and XP

Friday, April 25th, 2008

A remote vulnerability exists in the QuickTime player for Windows XP and Vista (latest service packs). Other versions are believed to be affected as well. For now, no details will be released regarding the method of exploitation. Because we are an information security think tank and because we encounter some very ...

Opera boosts its anti-phishing defenses

Friday, April 25th, 2008

Opera 9.5 Beta 2 has stepped up its security game. The browser has added fraud protection and support for EV SSL (Extended Validation Secure Sockets Layer) certificates to help prevent identity theft. Opera’s move to join the EV SSL crowd leaves Safari as the only browser without anti-phishing protection. As you ...

Details of privilege escalation hole in Windows

Monday, April 21st, 2008

In a security alert last week, Microsoft reported a vulnerability which allows local users and users signed on with access to an Internet Information Server (IIS) or MS SQL server to escalate their privileges. Server operators such as hosting providers who allow user code to be executed, for example on ...

Solutions Superguide: 529 Tips for Better Computing

Monday, April 21st, 2008

There's a ton of information in your computer's user manual, but it's also hundreds of pages long. To become a real power user, you could read through the entire thing, memorizing the details on each page. Or you could turn to PC Magazine. For this very special feature, we'll boil down ...

New Compression Tool Triples Network Storage

Sunday, April 20th, 2008

Storwize has developed a new range of in-line data compression appliances which it claimed can compress files at up to 500MB/s, doubling or even tripling the effective capacity of a NAS array. The three new systems are 64-bit, meaning they can use far more memory than the company's previous models. That ...

Red Hat to focus on enterprise market, not consumer Linux

Thursday, April 17th, 2008

Once upon a time when you mentioned Linux to non-Linux users, the first thing they thought of was Red Hat. That's because the company was one of the first and most successful to get its desktop Linux onto retail shelves. But in a blog post today, the Red Hat team ...

Quick Vista Hack to Get You Browsing at High-Speed Again

Thursday, April 17th, 2008

I’m not a Windows Vista fan. In fact, my new PC runs on XP, but uses OpenSource applications for most of my business needs. So why do I even care about a trick to get sluggish Vista browsing back to an acceptable speed? My mom uses Vista, and I love ...

Hacker releases working GDI-bug attack code

Wednesday, April 16th, 2008

Security researchers on Monday spotted malicious code that triggers a critical vulnerability in the Chinese version of Windows 2000, and warned users of other editions to expect attacks. Symantec confirmed that the proof-of-concept code publicly posted to the milw0rm.com site earlier in the day successfully attacks Chinese editions of Windows 2000 ...

Hackers exploit poor website code

Monday, April 14th, 2008

Many of the loopholes left in the code created for websites have been known about for almost a decade say the security researchers. The poor practices are proving very attractive to hi-tech criminals looking for a ready source of victims. According to Symantec the number of sites vulnerable in this way almost ...