DNS flaw is so big it puts every network at risk

Thursday, August 7th, 2008

A recently found flaw in the internet's addressing system is worse than first feared, so Dan Kaminsky said when speaking publicly about his discovery at the Black Hat conference in Las Vegas.He said fixes for the flaw in the net's Domain Name System (DNS) had focused on web browsers but ...

A Safer Gmail With Https

Friday, July 25th, 2008

Google added a new feature to Gmail to always use a secure (https) connection. Switch to the settings/ general tab and scroll down to “Browser connection” to see if you got it already (if not, it may still be rolled out for you). While safer, Google in their blog announcement ...

DNS blacklist for weak SSL keys

Tuesday, July 1st, 2008

Working closely with the German hosting company – manitu, heise is making available with immediate effect a realtime DNS-based blacklist service for identifying weak SSL keys. The provider already runs the Realtime Blacklist for the iX spam filter NiX Spam, which enables mail servers to identify and filter spam.The principle ...

Cain & Abel v4.9.15 released

Saturday, June 21st, 2008

Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords ...

Details emerge of Safari “carpet bomb” flaw

Monday, June 16th, 2008

The vulnerability known as the Safari carpet bomb has still not been fixed, despite Microsoft releasing a security update for Internet Explorer last Tuesday evening. The consensus is that Microsoft's browser is the main cause of the problem, which can create a security hole in combination with Apple's Safari. When Internet ...

Cisco alums readying firewall killer

Monday, May 19th, 2008

Five former Cisco engineers have co-founded a start-up called Rohati Systems whose products take dead aim at traditional perimeter firewalls. A traditional firewall and its access control lists "is not capable of doing its job today from an access-control perspective," says CEO and President Shane Buckley. "Nowadays, your ...

Debian and Ubuntu keys under attack

Friday, May 16th, 2008

A recently disclosed vulnerability in widely used Linux distributions can be exploited by attackers to guess cryptographic keys, possibly leading to the forgery of digital signatures and theft of confidential information, a noted security researcher said Thursday. HD Moore, best known as the exploit researcher who created the Metasploit penetration testing ...

YubiKey - One-time Password and Authentication Device

Saturday, April 26th, 2008

It works seamlessly with any hardware and operating system combination supporting USB keyboards such as Windows, MacOS, Linux and others. The Key generates and sends unique time-variant authentication codes by emulating keystrokes through the standard keyboard interface. The computer to which the Key is attached receives this authentication code character ...

Opera boosts its anti-phishing defenses

Friday, April 25th, 2008

Opera 9.5 Beta 2 has stepped up its security game. The browser has added fraud protection and support for EV SSL (Extended Validation Secure Sockets Layer) certificates to help prevent identity theft. Opera’s move to join the EV SSL crowd leaves Safari as the only browser without anti-phishing protection. As you ...

PayPal Plans to Ban Unsafe Browsers

Thursday, April 17th, 2008

PayPal says allowing customers to make financial transactions on unsafe browsers "is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts." PayPal, one of the brands most spoofed in phishing attacks, is working on a plan to block its users from making transactions from ...