New Google bugs empower phishermen

Saturday, October 11th, 2008

Google's Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users' login credentials, a security expert has demonstrated. Google Calendar and other sensitive Google services are susceptible to similar tampering. A proof-of-concept (PoC) attack, published by Adrian Pastor of the GNUCitizen ...

Firefox Extension Blocks Dangerous Web Attack

Wednesday, October 8th, 2008

A popular free security tool for the Firefox browser has been upgraded to block one of the most dangerous and troubling security problems facing the Web today. NoScript is a small application that integrates into Firefox. It blocks scripts in programming languages such as JavaScript and Java from executing on untrusted ...

Web Gives Hackers More Territory, Tools

Sunday, September 28th, 2008

As more people become accustomed to Web surfing and downloading software and multimedia, legitimate Web sites have become the favorite targets of hackers. "The hacking of legitimate Web sites is the biggest threat today," said David Freer, Symantec's vice president for consumer business in Asia-Pacific and Japan. Freer revealed that based on ...

Trojan can grab extra personal banking data

Saturday, September 27th, 2008

A Trojan horse program now available to a growing number of fraudsters can add data entry fields to legitimate online banking sites and entice consumers to give up sensitive information such as bank card numbers and PINs (personal identification numbers). The Limbo malware integrates itself into a Web browser using a ...

CSRF vulnerability allows Twitter ‘follow’ abuse

Thursday, September 11th, 2008

Last week, TechCrunch’s Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called “johng77536″ to game the popular micro-blogging service to add thousands of followers (subscribers) in a short period of time. The “johng77536″ account has since been disabled but a security researcher tracking Twitter security flaws and ...